fraudulent apps

AppWizard
July 31, 2026
Bitsight's investigation revealed that inexpensive Android TV boxes are being shipped with applications that can change their hardware identity, allowing them to impersonate popular smartphone brands like Samsung and Huawei. This operation, named Fuyao, is linked to Zhejiang Fengwo IoT Technology Co., Ltd., a Chinese company established in 2019. The H96MAXV11 model was frequently reported among the affected devices. In one day, the operation received 65,957 reports from about 38,000 unique MAC addresses, with many devices misidentified as phones due to spoofed identifiers. Fengwo has also promoted over 120,000 "AI digital humans," though details on this marketing term are vague. The command-and-control server for Fuyao sends phone profiles to devices, masking their actual hardware specifications. The operation uses machine vision technology and a YOLOv8s object-detection model to identify advertisements. Bitsight documented 40 fraud tasks, 21 unique campaigns, and 166 modules across four devices. The operation's payout structure involves 144 operator-owned domains, with an estimated gross return of .25 per device daily, potentially leading to annual revenues in the millions. Attribution to Fengwo is supported by shared TLS certificate data and public patent records, although the patents do not directly address advertising. There is uncertainty about how the fraudulent apps were installed and at what point in the supply chain they were introduced. Device owners are advised to verify Play Protect certification and disconnect suspicious devices.
AppWizard
June 6, 2026
Arabic-speaking users are the target of a new Android spyware called Asin, identified by ESET in early 2025. The malware is distributed through fraudulent websites that mimic legitimate services, including: - govlens[.]net, registered on May 27, 2025, impersonating a government news source. - pdf-reader[.]help, registered on May 29, 2025, claiming to be a secure PDF editor. - live-war-map[.]com, registered on January 20, 2025, providing updates on military incidents. Two of these domains are promoted via social media accounts on Facebook and Telegram. The spyware combines legitimate functionality with covert capabilities, and its campaigns may target journalists and OSINT researchers in Arabic-speaking regions. Artifacts linked to Asin include an upload to VirusTotal from Türkiye in October 2025, an APK downloaded from c-pdf[.]net in December 2025, and a sample disguised as "Syria Defense Map" detected in January 2026. Users must manually install the applications and grant permissions for the spyware to operate.
AppWizard
May 9, 2026
Cybersecurity researchers from ESET have discovered 28 fraudulent applications on the Google Play Store that falsely claimed to provide access to call histories for any phone number. These apps have been downloaded over 7.3 million times, with one app alone accounting for over 3 million downloads. The operation, named CallPhantom, primarily targeted Android users in India and the Asia-Pacific region. Users were lured into subscription services, paying for access to fictitious data, including call histories and SMS records, but received only randomly generated information. Some apps were published under the developer name "Indian gov.in" to create a false sense of trust. Payments were processed through the Google Play Store or third-party applications like Google Pay and Paytm. Users who subscribed via Google Play may be eligible for refunds, while those who used third-party payment methods may not be able to recover their funds. The fraudulent activity may have been ongoing since at least November 2025.
Search