However, by entering their information, users were actually submitting their phone number to an SMS service that would start charging their phone bill about $42 per month. “Forensic evidence of this active Android Trojan attack, which we have named GriftHorse, suggests that the threat group has been running this campaign since November 2020,” Zimperium stated in their findings. “These malicious applications were initially distributed through both Google Play and third-party application stores.”
Zimperium, a member of the Google App Defense Alliance which scans applications before publishing in the Google Play Store, estimates that 10 million Android users globally were affected by this scam. The applications posed as seemingly normal downloads, hiding under facades like “Photo Effect Pro,” “Daily Horoscope & Life Palmestry,” and “Free Coupons 2021.” The apps would notify downloaders that they won a prize and would redirect them to enter their phone number on a specific webpage.
Scams like GriftHorse take advantage of small screens, local trust, and misinformation to trick users into falling for their scams and downloading their apps, Zimperium explained. They also prey on “frustration or curiosity” when they try to accept their fake prize. According to Zimperium, the “level of sophistication, use of novel techniques, and determination” of the threat actors had allowed them to remain undetected.
Google says that all of the apps identified by Zimperium have been removed and the developers of the apps have been banned, but the scam will have lasting effects, WIRED reported. Android users who have not stopped the charges have faced unwanted additions to their wireless bill of over $230.
To prevent scams, the Federal Communications Commission recommends consumers “think twice” before clicking any links and to report any unusual activity. If you sent money to a scammer, the Federal Trade Commission recommends your report the payment right away to reverse the transaction before filing a report with the FTC who can build a case against the scammers.