Fake PDF update adverts: CERT explains the Messenger Pro trap
CERT Polska linked fake PDF update adverts to a malicious Messenger Pro app. Check the mismatch, installed apps and unfamiliar mobile charges.
In an analysis published on 23 September 2026, CERT Polska described adverts for a supposed PDF update that led to Messenger Pro. Our Sunday security review revisits the findings because they concern everyday phone use.
A PDF advert leading to a messaging app
Researchers linked the application to abuse of paid services charged through mobile operators. The initial warning sign was a mismatch: the advert concerned PDF files, while the offered installation was a messaging application.
Removal from a store is not removal from a phone
CERT says Google removed the identified app following a report, but that does not automatically remove previously installed copies. The findings concern a specific tested application; a similar name alone is not evidence against another messenger.
Practical checks for users
Our practical suggestion is to close an alarming advert and independently open your update settings. Review recently installed software and the app currently handling SMS messages. Do not grant message access simply because a screen promises a convenient feature.
If unfamiliar charges appear, record the service names and dates shown on your bill and contact your operator about clarification and available blocking options. The official CERT website links to incident reporting. Preserve the evidence without publicly sharing your telephone number or billing details.
This article and translation were prepared with AI assistance. How we work