Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. Web
  6. News

Don’t open this dangerous text message unless you want to lose control of your Android

Add as a preferred source on Google

Do not, on pain of Android death, open this text message. A dangerous piece of correspondence, first spotted by Norwegian security firm Heimdal, is said to effectively hand the reigns of your mobile device over to malicious hackers, who can then wipe the phone clean, or worse yet, make calls or texts on your behalf. The message contains a link to an application, and the text itself reads, “You have received a multimedia message from +[country code] [sender number] Follow the link http:www.mmsforyou [.] Net /mms.apk to view the message.”

Immediately thereafter, according to Metro.uk, “The application installs the application Tor and then sends an automated text message to a number in Iran saying, ‘Thank you.’” Truly terrifying.

Recommended Videos

Heimdal believes that this malicious text has been sent to over 100,000 in Denmark alone, and it is yet unclear as to whether residents of other countries have received the message. That said, there appears to be one small caveat to the text’s effectiveness — if the phone’s language is set to Russian, the dangerous app will not install.

The implications of this sort of uninvited administrator access to your smartphone are serious, Heimdal points out. Given that your phone is used to verify two-factor authentication mechanisms (often considered one of the more secure forms of protection), ceding control of your phone to a hacker can lead to identity theft, and thereafter, property theft.

“Attackers can open a backdoor into Android smartphones, to monitor and control them as they please, [and] read SMS messages,” the security firm says. This means hackers “can also read authentication codes sent as part of two-factor authentication mechanisms, used also by online banking apps and e-commerce websites, and use their full access to Android phones to basically manipulate the device to do whatever they want.”

So what can you do to protect yourself? Don’t set your phone to Russian, first of all (unless you read the language, of course). Instead, Heimdal suggests, “NEVER click on links in SMS or MMS messages on your phone. Android phones are notoriously vulnerable and current security products dedicated to this OS are not nearly as effective as they are on computers.”

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
TSMC might set up a price hike that could come straight for your next phone, laptop, or tablet
Here's what TSMC's rumored 10% chip price increase actually means in dollar terms, and why your next phone or laptop could end up costing more.
TSMC Fab

My wallet flinched the second I saw the words "TSMC" and "price increase" in the same headline, and honestly, yours should too.

Turns out the company behind the silicon powering basically every flagship device out there, including Apple’s A-series and Qualcomm’s Snapdragon processors, is reportedly about to make all of it a little pricier.

Read more
Samsung’s free storage doubling for preorders is gone in Austria, and the replacement isn’t as sweet
Samsung's free storage doubling deal might just be history.
The back of the Galaxy Z Fold 7

If you've pre-ordered a Samsung foldable purely for the free storage bump, tomorrow's Unpacked event might sting a little.

For years, pre-ordering a new Galaxy meant automatically getting double the storage at no additional charge. Buy the 128GB model, walk away with 256GB for the same price. The same applied to the 256GB and 512GB models. However, that might change at the upcoming Galaxy Unpacked event. 

Read more
Apple fixes Hide My Email bug that exposed users’ real email addresses
Here's how Apple's Hide My Email flaw leaked real addresses for over a year, and why it only got fixed once the story went public.
apple-merging-sign-in-with-apple-hide-my-email-icloud+

Turns out the "Hide" part of Hide My Email wasn't doing its job quite as advertised, something that I covered early in July. Security researcher Tyler Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable, at least until July 3, 2026.

So how did this bug actually work?

Read more