Hidden malware stealing money from your phone – 200+ fake apps exposed
A sophisticated cyberattack, targeting over 200 fake Android apps mimicking popular apps like TikTok and GTA, is quietly draining users’ bank accounts through their mobile carriers. Cybersecurity firm Zimperium has uncovered a multi-pronged scheme, revealing a worrying level of sophistication and a persistent threat still active today.
The three-fold attack: how it works
This isn’t your average malicious app. The operation, reportedly originating in Romania, Malaysia, Thailand, and Croatia, leverages a layered approach, bypassing standard security protocols. First, it employs automated subscription engines to trick users into subscribing to premium services without their knowledge. Then, a disturbingly precise SIM card reader intercepts data, identifying the user’s carrier. Finally, a cleverly designed social engineering page mimics legitimate confirmations, masking the fraudulent activity.

200+ Apps, few on the play store
While Google Play Protect is designed to block known threats, a staggering 200+ apps – and 249, to be precise – were used in the scam. Remarkably, none of these malicious applications appear on the official Google Play Store. This highlights the ease with which these deceptive apps can proliferate and the urgent need for heightened user vigilance.

Regional focus – malaysia hit hardest
Malaysia accounts for 85% of the victims, with DiGi, a prominent Malaysian carrier, being specifically targeted. Thailand and Romania represent approximately 15% of the attacks, while Croatia saw a comparatively minor impact. The scheme targeted over 30 carriers globally, including names like Marxis, Celcom, and U Mobile.
The attack isn’t over
Despite initial detection in March 2025, Zimperium reports that elements of the underlying infrastructure remain operational. Activity peaked in September 2025, but the potential for reactivation looms large. Users should be acutely aware that this isn’t a closed case; it’s a dormant threat waiting to trigger.
Protecting yourself – a simple checklist
Don’t download apps from unofficial sources. Scrutinize app permissions carefully. Never enter sensitive information – passwords, credit card details – unless you’re absolutely certain of the website’s legitimacy. And remember, a little skepticism goes a long way in safeguarding your digital assets.