Modobom WAP Fraud (provisional)

Malware family · 2 sample(s) · 9 indicator record(s) · 1 signing certificate(s) · Active 2026-10-07 → 2026-10-10 (experimental)

About Modobom WAP Fraud (provisional)

Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Also covers the “Ender Inspector” variant (com.mi1hgr85yq.j5z43) whose Modobom SDK pulls tasking from apitoken.phoemobi.com and lperc.modobomco.com (shared infra across the cluster). Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
apitoken.modobomco.com domain f63166f41ac9… 2026-10-07
apitoken.phoemobi.com/fuvi_4541341.php domain 266b1c7134da… 2026-10-10
lpbigfun.thacyber.com domain f63166f41ac9… 2026-10-07
lperc.modobomco.com domain f63166f41ac9… 2026-10-07
lperc.modobomco.com/ domain 266b1c7134da… 2026-10-10
lpflavornest.mdb.guru domain f63166f41ac9… 2026-10-07
onesignal5.modobomco.com domain f63166f41ac9… 2026-10-07
sunny-mobi.com domain f63166f41ac9… 2026-10-07
wap.lpalice2appsmart.com domain f63166f41ac9… 2026-10-07

Operators / owners (1)

Operator handles recovered from sample configuration (for example the owner_username baked into the C2 panel). Click to list that operator's indicators.