Paid advertising carried the malware, and the takedown reached the store, not the handsets
A national CERT’s investigation into Android apps promoted through Meta ads shows the limit of platform enforcement: removal stops new installations and leaves existing ones running.
The Register reported on 24 September that malicious Android applications, promoted with paid Meta advertisements, steered Polish users into premium-rate billing subscriptions. A national CERT reported an app identified as “Messenger Pro” to Google on 15 September and reported each further app uncovered as the investigation continued; Google removed the identified apps from Play and Meta removed the advertisements researchers flagged. The outlet’s framing is the part worth keeping: delisting stopped new installations through those pages and did nothing about copies already sitting on devices. The Register is reporting a named CERT’s published research rather than an anonymous source, though our retrieval did not capture which national body — CERT Polska is the obvious candidate given the target population and is not confirmed here. No install count, revenue figure or victim total appeared in the retrieved text.
The same asymmetry governs the commercial spyware file, where delivery is purchased and persistence is the product. Citizen Lab, working with the SHARE Foundation, confirmed on 2 September that a member of Serbia’s student protest movement was infected with Pegasus, stating that its analysis “confirmed that an iMessage zero-click exploit was used to infect the device” and noting the finding does not preclude additional infections; Cybernews reported at least 14 people targeted in Serbia around early-2026 local elections, including activists, an opposition MP and a local councillor. Citizen Lab posted an item around 24 September titled “UN Reports Citing Citizen Lab Submissions Published.” We have not read the post or the underlying UN documents, do not know which UN body issued them, and make no claim about what they contain.
Meta’s own disclosures sit in the same category of partial visibility. Axios reported exclusively on 27 August that the company had disrupted an Iran-linked operation using artificial intelligence against politicians and journalists, with Meta’s accompanying position being that AI-generated content is now routine in influence operations. That is a single outlet relaying a company’s account of its own enforcement — a claim about what was removed, not an independently verified account of what was run. The primary document is Meta’s H2 2026 Adversarial Threat Report, which should be read before the episode is characterised further.
Assessment: Enforcement metrics measure the enforcer. Platforms report what they took down, never what remains resident, and the Polish case makes the gap legible: the advertisement is the cheap, replaceable layer, and the installed binary is the durable one. Expect the same structure wherever ad networks reach Gulf and Levantine audiences — the takedown will be announced, the residue will not be counted. Two cautions for the coming week. Citizen Lab forensics entering UN documentation would change the standing of commercial-spyware evidence, but that is a hypothesis about a post nobody on this desk has opened. And an undated Citizen Lab finding that a former PEGA committee member was hacked with Pegasus is circulating without a publication date. If recent, it is the week’s strongest item; until dated, it is not an item at all.