Also available in Persian — نسخه فارسی EN فا
❓ Unknown

How Cyber Saboteurs Inflate Your Mobile Bill?

Jan 25, 2026 January 25, 2026 4 min read 📰 Radio Farda
📋 Key Takeaway

A report reveals that a network of malware called PushIran.DL is infecting Android devices in Iran, potentially affecting over 10 million devices. The malware exploits telecommunications value-added services to generate income for its developers through unauthorized charges to users' mobile bills. This situation highlights significant cybersecurity risks for Android users in Iran.

🔍 Quick Context Guide
💡 Bottom Line: The PushIran.DL malware poses a serious threat to millions of Android users in Iran, leading to unauthorized charges and highlighting the need for better cybersecurity practices.

👥 Key Players

PushIran.DL Developers MENTIONED
Creators of the malware
"They are responsible for the widespread infection of Android devices in Iran, impacting millions of users."
Raman and Raz MENTIONED
Mobile application development companies
"They are identified as the main developers behind the PushIran.DL malware, indicating a potential link between legitimate business operations and cybercrime."
Android Users in Iran MENTIONED
Victims of the malware
"They are directly affected by unauthorized charges and cybersecurity risks, highlighting the need for awareness and protection."

📰 What Happened

A report reveals that a network of malware called PushIran.DL is infecting Android devices in Iran, potentially affecting over 10 million devices. This malware exploits telecommunications value-added services to generate income for its developers through unauthorized charges to users' mobile bills.

  • PushIran.DL malware is believed to infect at least 10 million Android devices in Iran.
  • The malware generates income by exploiting telecommunications services, leading to unauthorized charges on users' mobile bills.

💡 Why It Matters

🇮🇷 For Iran: This situation raises significant cybersecurity concerns and highlights the vulnerabilities of mobile users in Iran.
🌍 Regional: It underscores the need for enhanced cybersecurity measures in the region, where mobile technology is increasingly integral to daily life.
🌐 International: International cybersecurity experts may take interest in the malware's implications for global cybersecurity trends and the potential for similar attacks elsewhere.

📚 Background

Cybersecurity threats are a growing concern globally, and malware targeting mobile devices can lead to significant financial and privacy risks for users. In Iran, where mobile technology is widely used, such threats are particularly alarming.

Cybersecurity in Iran Mobile technology vulnerabilities
📡 Source: NEUTRAL
📊 Confidence: 70%
The report appears to be based on research findings, but readers should consider the potential for bias based on the author's affiliations.

Since the beginning of 2018, I and several others have been working on a network of malware called PushIran.DL, the results of which we recently published in a comprehensive report on the website Sartefa, which I founded. This relatively long report, about 20 pages, contains important points for Android users in Iran, which is why this article has been written. Therefore, I strongly recommend that you send this article to your friends and acquaintances, as their Android devices are likely also infected with one of the PushIran.DL malware. The structure of PushIran.DL consists of various malware that introduce themselves to users under different names, such as "Which Actor Are You Like?", "Mushroom Eater", "18+ Collection", etc.; you can view a list of about 220 examples of these malware presented in various Android applications here. Additionally, we believe that at least 10 million Android devices in Iran are infected with this malware. The main developers and designers of PushIran.DL are two companies, Raman and Raz, which operate in mobile application development, online advertising, and online marketing in the country. According to what has been registered in the official newspaper of the country, these two companies began their official activities in the spring and summer of 2017. The goal of the developers of PushIran.DL is to earn money through various methods, such as exploiting telecommunications value-added schemes or illegally increasing the download rates of various applications in various Android application stores like Cafe Bazaar. The first and perhaps most important function of PushIran.DL malware relates to the use of telecommunications value-added services (VAS), which allows the designers of this malware to earn direct income from infected devices. For this purpose, the designers of PushIran.DL contract with VAS service providers and then receive a percentage as a commission from these companies. For example, the table below shows the daily income of 118 million tomans for VAS providers through 10 PushIran.DL applications, assuming a 1% commission, the developers of this malware family would earn a daily income of 1 million and 200 thousand tomans! The remarkable income of VAS companies also stems from the fact that PushIran.DL developers add the capability to activate VAS services via SMS as a commercial feature to their infected apps, and then start charging users daily. This daily charge, which is deducted from the victim's SIM card balance or added to their monthly bill, ranges from 200 to 400 tomans per day. In addition to this method, the developers of PushIran.DL use their malware network to forcibly install various applications on victims' devices, increase views of Telegram and Instagram posts, display advertising pop-ups, engage in click fraud to boost website views, and direct users to various pages and websites, such as value-added service websites. For example, the image below shows two examples of advertising pop-ups that PushIran.DL forcibly displays on users' devices. I must point out that if you see such messages on your Android device for any reason, know that your smartphone or tablet is infected with one of the PushIran.DL malware. The first step to countering PushIran.DL malware is to install an antivirus on your mobile phone or tablet. According to our research, the following antivirus programs can identify malware produced by PushIran.DL: Dr.Web, Avira, ESET NOD32, Kaspersky, Trend Micro. Make sure to download these antivirus programs from Google Play or Cafe Bazaar and never download APK files from other sources or Telegram channels. Additionally, always keep the installed antivirus updated. Besides installing and updating antivirus software, always check the comments section of a new application before installing it to read other users' opinions and ensure the authenticity of the application. This recommendation is due to the fact that in many cases, it has been observed that PushIran.DL designers have released an application under a name while that application does not have such functionality. Furthermore, be cautious when receiving various notifications and do not click on a notification without checking it, nor grant various permissions to different applications. Finally, strongly avoid installing applications like fortune-telling apps, "Who Do You Resemble?", "When Is Your Future Love?", etc., and do not install them under any circumstances. You can read the full report "The PushIran.DL Malware Family, A Fraudulent Advertising Botnet in Iran" here.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →