CERT Polska traced 852 of the 1,235 Meta ads it preserved to 17 apps on Google Play built to sign Polish Android users up for paid services they never agreed to, with six confirmed to carry the billing malware and the rest sharing its loader. The first lead was two Facebook ads that falsely told users their PDF app had expired, which opened Messenger Pro, a texting app that downloaded the fraud code after install. Victims were charged 30.75 PLN per message sent to premium short codes, or 17 PLN a week through a carrier-billing subscription, with the costs landing on their phone bills. Google pulled the apps and Meta removed the reported ads, but the operation’s servers kept running and new apps appeared afterward, so copies already installed could still bill users.






