Modobom WAP Fraud (provisional)
Malware family · 1 sample(s) · 7 indicator record(s) · 1 signing certificate(s)
About Modobom WAP Fraud (provisional)
Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| apitoken.modobomco.com | domain | f63166f41ac9… | 2026-10-07 |
| lpbigfun.thacyber.com | domain | f63166f41ac9… | 2026-10-07 |
| lperc.modobomco.com | domain | f63166f41ac9… | 2026-10-07 |
| lpflavornest.mdb.guru | domain | f63166f41ac9… | 2026-10-07 |
| onesignal5.modobomco.com | domain | f63166f41ac9… | 2026-10-07 |
| sunny-mobi.com | domain | f63166f41ac9… | 2026-10-07 |
| wap.lpalice2appsmart.com | domain | f63166f41ac9… | 2026-10-07 |