SMS malware is a topic old as coal on the darknet, there is even a tutorial on the hidden wiki; what I'm curious about is where those apps are distributed, AFAIK google play deals with it (at least the obvious sms ones) pretty well. From what I hear people complaining often on HN, in the US carriers are tied with Google. Meanwhile here in Poland I rarely see a phone that has google apps out of the box (usually there is some crapware from the carrier, a shitty nav app instead of gmaps, and maybe a youtube app and that's it) and external appstores are unlocked by default - I can assume it's a similar situation in Russia and those malicious apps are distributed through some local app stores. Can somebody from Russia comment on that?