Skip to main content

Malvertising Supply Chain: 1,235 Ads & 74 Profiles Exposed

CERT Polska's September 23, 2026 report details a major toll fraud campaign involving 1,235 Meta ads, 74 profiles, and 29 Google Play apps.

AI-written
Inewgen
10 Oct 2026Source: Dev.to4 min read (0 views)
Share
Malvertising Supply Chain: 1,235 Ads & 74 Profiles Exposed

Stock photo for illustration only, not from the actual event

Font size
  • CERT Polska uncovered 1,235 Meta ads across 74 profiles promoting 29 Google Play apps.
  • At least 6 apps confirmed containing toll fraud components and malicious loaders.
  • The campaign heavily reused ad creative files with identical SHA-256 hashes across profiles.
  • ZoomEye infrastructure queries revealed that campaign endpoints remain nearly invisible.

The investigation published by CERT Polska on September 23, 2026, began with just two Facebook advertisements and culminated in a retained set of 1,235 unique Meta ad records displayed under 74 identified profile names, promoting 29 applications on Google Play. These numbers outline the distribution arm of a sophisticated operation.

This campaign highlights a severe supply-chain flaw that standard platform reviews failed to catch, as the advertisements themselves did not contain malicious files, and the promoted applications were functional messaging and utility tools that bypassed automated store filters seamlessly.

smartphone mobile app screen interface

Stock photo for illustration only, not from the actual event

The threat actors aggressively reused advertising files throughout the operation. Analysts collected 898 additional ad files and grouped them into 45 sets featuring identical SHA-256 hashes. Twenty-three of those sets matched files from earlier collections. For instance, an unchanged file with SHA-256 hash 90b87d8b4dda273ef64853a9997bba0844f0bc02071ae5101d1be2693be1b861 appeared in 55 new ads covering 20 packages and 39 identified profiles. Another file with SHA-256 hash 7299f7de6acf366fc7f32f7c3873a09e11a08d9493aaa508cd2b2ee816c5d284 surged from 26 ads to 50.

Multiple identical creative files spread across dozens of profiles indicate coordinated campaign preparation rather than independent advertisers copying each other. Fifty-nine low-reputation display names carried the targets, including profile links such as Britney Harris (62 ads), Joshua Wilson (55), James Davis (42), Sarah Anderson (36), and Mary Garcia (33).

Modern malvertising campaigns leverage clean-looking social media ads combined with everyday utility apps as a high-level social engineering strategy. By exploiting the inherent trust of major platforms, threat actors bypass user skepticism and automated filters until deep code-level and infrastructure analysis reveals the underlying malicious mechanics.

Seventeen applications promoted in 852 ads under 60 profile names were linked to the operation through code or infrastructure evidence. Key confirmed samples include:

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

  • Cool Wallpaper: 153 ads, confirmed toll fraud sample.
  • Text Chat: 135 ads, confirmed toll fraud sample.
  • Seed Text Messages: 133 ads, confirmed loader linked to the operation.
  • Max Messenger: 121 ads, confirmed toll fraud sample.
  • Instant Messages: 99 ads, confirmed loader linked to the operation.
  • Messenger Pro: 49 ads, confirmed toll fraud sample.
1,235Meta Ad Records
74Profile Names
29Google Play Apps

CERT Polska reported the malicious applications to Google, which subsequently removed them from the store, and reported the ads to Meta for removal. However, these actions remain partial by design, as other ads in the operation may have stayed active or expired naturally, and the command-and-control (C2) infrastructure continued responding even after store takedowns.

digital marketing advertisement analytics dashboard

Stock photo for illustration only, not from the actual event

Infrastructure queries executed via ZoomEye on September 24, 2026, between 05:13 and 05:16 UTC returned counts such as 1,995 matches for domain="aliyuncs.com" and 44 matches for domain="oss-ap-southeast-1.aliyuncs.com". These figures demonstrate that the operation's endpoints are virtually invisible within service data, blending seamlessly into ubiquitous cloud storage brands.

cloud storage network infrastructure data center

Stock photo for illustration only, not from the actual event

Source: Dev.to

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article