The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions.
A 10-month Android malware campaign has used nearly 250 fake apps to sign victims up to premium services on their mobile ...