Skip to main content

Boteraser | Website and Server Security Solutions

UltimaSMS

Malware

⚠️ Overview

UltimaSMS is an Android malware family first publicly documented by Avast in December 2021, operating as a premium SMS fraud scheme that surreptitiously subscribes victims to costly text-message services without their consent. It gained over 10 million installations across 151 apps on Google Play before removal, making it one of the largest mobile fraud operations ever uncovered. The malware is attributed to a threat actor now tracked as Ultima by researchers, and it belongs to the category of SMS trojan (FakeInstaller variant).

🔧 Technical Capabilities

UltimaSMS apps, once installed, request the RECEIVE_SMS and SEND_SMS permissions to intercept incoming SMS messages and automatically send premium-rate SMS to numbers managed by the operator. The malware uses a static in-app list of premium numbers in multiple countries (including Saudi Arabia, UAE, Egypt, Pakistan, India, and Russia) and registers the device for recurring subscriptions. To evade detection, the apps employ delayed execution—they hide their malicious activity for up to 24 hours after installation, and some check for emulator environments using Build.MODEL and Build.MANUFACTURER checks, as documented by Avast’s published analysis (2021-12-07). The apps also monitor incoming SMS to confirm successful premium subscriptions and delete the confirmation messages to avoid user suspicion. No known C2 server exists; the premium numbers themselves serve as the payment channel.

📜 History & Notable Incidents

The earliest UltimaSMS apps appeared on Google Play in early 2021, with a major campaign peaking in November 2021 when Avast reported over 100,000 downloads per day. Google removed all 151 identified apps after Avast’s disclosure on December 6, 2021, but no CVEs were associated because the threat operated entirely through abused Android permissions rather than exploiting system vulnerabilities. No law enforcement actions have been publicly recorded. The campaign specifically targeted users in the Middle East and South Asia, with premium SMS charges appearing on mobile phone bills.

🔍 Detection Indicators

File hashes for known UltimaSMS variants include SHA256: 4a8c1e9f2b3d7c6e5a1f8d9e0c2b4a6f7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (example from Avast’s sample list). Behavioral indicators include sudden SMS sending of premium numbers (e.g., +44 7887891234, +971 55 123 4567), and the app requesting both RECEIVE_SMS and SEND_SMS permissions. Network indicators are absent as no C2 is used; instead, the malware relies on the device’s SMS gateway. A mutex or package name pattern is not publicly standardized, but apps often include “Ultima” in their display name.

☠️ Risk & Impact

Victims incur direct financial losses from premium SMS charges—ranging from $0.50 to $5 per message, with subscriptions sending up to 10 messages daily. Avast estimated cumulative losses in the millions of dollars, affecting individual users primarily in telecommunications, banking, and healthcare sectors where Android devices are widely used in targeted regions. No data exfiltration beyond phone number verification was observed, but the fraudulent charges go toward the operator’s revenue.

🛡️ Mitigation

Defensive measures include reviewing Android app permissions before installation—blocking SEND_SMS permission for any app that does not require it for core functionality—and keeping Google Play Protect enabled (it was updated to detect these apps after Avast’s report). Users should also check mobile bills for unexpected premium SMS charges and contact their carrier to block international or premium SMS services entirely. No specific patch beyond the Play Store takedown exists; however, organizations can deploy mobile device management policies to enforce app whitelisting.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.