An SMS Trojan was spotted in the Google Play marketplace, distributed via a series of wallpaper apps that may look legitimate at first glance. The apps connect to a Dropbox account to download an additional package named Activator.apk Bitdefender Labs has found three other apps that exhibit the exact same behavior. The Trojan acts by identifying the current mobile operator you`re subscribed to by matching two separate strings [bBeEeE]* and mtTsS and then sending two premium SMS messages instead of one to the 3170 phone number.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/sms-malware-in-google-play-marketplace/

