Skip to content
KhaiziNam Blog KhaiziNam Blog
Go back
Đọc bằng tiếng Việt

Decoding Black MMO Pay In-App: What Is It?

Nguyễn Hữu Khải - khaizinam

1. Introduction

In the digital age, Pay in-app (in-app purchasing) has become an indispensable part of the experience, allowing users to easily buy game items, upgrade service packages, or subscribe to memberships with just a few taps.

In the digital age, Pay in-app has become an indispensable part
In the digital age, Pay in-app has become an indispensable part

However, behind this convenience lies a “dark corner” of the Black MMO world, where Pay in-app is defined as a sub-branch of Carding - a form of fraud that uses stolen (hacked) international payment card information to perform unauthorized shopping or payment transactions.

Current trends show an explosion in these fraudulent activities through mobile payment gateways, as bad actors exploit system security loopholes for profit.

This article aims to provide a multi-dimensional look at device “spoofing” techniques, the operational process of card info (Ci) hijacking rings, as well as the serious legal and ethical risks involved. Through this, we hope to provide practical warnings so that users and app developers can protect themselves from sophisticated tactics in the digital environment.

Read more: Warning: “Black MMO PayinApp” Scams 2026

Table of Contents


2. What is Pay In-App in the Black MMO World?

In the world of Black MMO (illegal Make Money Online), Pay in-app is understood as a sub-branch of Carding. This is the act of using stolen international payment card information to pay for app packages, top up games, buy donate coins, or VIP upgrade services.

In the Black MMO world, Pay in-app is a branch of Carding
In the Black MMO world, Pay in-app is a branch of Carding

Instead of using personal finances, these individuals exploit the balances of others’ cards to earn profits of 20-30% by liquidating the purchased items.

2.1 Card Info (Ci) - The Core “Ingredient”

To perform Pay in-app, the most important “ingredient” is Card Info (Ci) - a complete set of payment card data. A basic Ci set usually includes:

2.2 Classification of Ci Levels

Depending on the level of detail and application, Ci is divided into 3 main types:

2.3 Frequently Targeted Card Issuers

The Pay in-app system exploits almost all types of cards from major international issuers due to their popularity and cross-border payment capabilities:

3. Operational Process of a Pay In-App “Ring”

Pay In-App activities in the underground world are no longer isolated acts but have transformed into professional operating systems, clearly categorized like a tech company. Each group in the chain has specific tasks to optimize profit and minimize the risk of being traced.

Operational process of a Pay In-App ring
Operational process of a Pay In-App ring

3.1 Hacker: The Source Data Collection Group

This is the first and most critical link, responsible for providing the raw “material” (Ci). Hackers use many sophisticated techniques to steal user card information:

3.2 Seller: The Intermediate and Market Coordination Group

Hackers often do not exploit the cards directly because the risk of leaving traces is very high. Instead, they resell the data to Sellers. This group acts as “distributors” on platforms such as:

3.3 Miner: The Direct Exploiter and Liquidator

Miners are the final link in the supply chain, responsible for the act of “hitting” (paying) the cards into applications to earn actual profit:

This hierarchy helps the ring operate smoothly: Hackers do not need to worry about small-scale liquidation, Sellers profit from price spreads, and Miners focus entirely on technical bypasses to “harvest money” from payment loopholes.

4. Security Bypass Techniques (Bypass Detection)

For a Pay In-App transaction to be successfully approved, the Miner must pass Google’s extremely strict behavioral scanning and device identification systems. The core goal is to make the system believe the device is being used by a “real user” and that the transaction is completely valid from the cardholder’s perspective.

Security Bypass Techniques
Security Bypass Techniques

4.1 Device Spoofing

Payment systems often collect device fingerprints to assess reliability. Miners use specialized tools like Michanger, BillingInjector, or Frameworks like Magisk and Xposed to deeply interfere with the system:

4.2 Network Proxy

Geographic location is key to avoiding card locks. Miners prioritize SOCKS5 Proxies over regular VPNs for several reasons:

4.3 Leak Testing (DNS Leak & Blacklist)

A small technical error can cause a card to “die” instantly. Miners perform deep checks before transacting:

4.4 Account Aging (Tut)

“Tut” (Tutorial/Trick) refers to the steps taken to build “trust” with the system by aging the account before starting to “hit” cards:

5. Common Liquidation Methods

The ultimate goal of the Pay In-App process is to turn virtual in-app values into cash or tradable assets. Here are the most common liquidation methods used by Miners:

Common Liquidation Methods
Common Liquidation Methods

5.1 Service Account Upgrades

This is a popular way to create cheap accounts flooded in the market:

5.2 In-App Virtual Currency and Gifts

This method leverages the donate (gifting) features of social media and livestreaming apps:

5.3 Game Items (Illegal Top-up)

The online game market is a gold mine for liquidation due to the massive player base:

5.4 Building Fake Apps (App Dev)

This is a sophisticated technique requiring programming knowledge to optimize profit and take control of the process:

6. Decoding Google Play Error Codes (Troubleshooting)

During the In-App payment process, Google’s security system frequently returns error codes to block suspicious transactions or due to technical issues. Understanding these codes helps users (or Miners) accurately identify the problem.

Decoding Google Play Error Codes
Decoding Google Play Error Codes

Below is a summary table of the most common error codes related to Google Play payment issues:

Error CodeDetailed DescriptionMain Cause
OR-CCSEH-26Insufficient balanceThe card does not have enough balance for the package or the minimum verification transaction.
OR-CCSEH-04”Trust” verification requiredSuspicious activities prompt Google to require verification of account reputation or payment profile.
OR-BAIH-04Bank declined paymentTransaction blocked directly by the issuing bank, usually due to suspected fraud or policy violations.
OR-CCSEH-21Invalid cardThis card type is not accepted as a payment method in Google’s system.
OR-CCSEH-25Expired cardThe card has passed its expiration date or has been completely blocked by the bank.
OR-CAC-01Profile country mismatchThe country in the billing address does not match the card or Google account’s country.
OR-ACH-02Bank account issueThe bank detects risk and proactively blocks or imposes transaction limits on the card.
OR-CCSEH-05Outdated User AgentThe browser or User Agent used is too old, causing errors in the system’s processing.

Understanding these error codes not only assists in troubleshooting but also serves as a basis for evaluating the quality of card data (Ci) and the effectiveness of the spoofing techniques used.

7. Risks and Warnings

To ensure professionalism and reliability, we must recognize that Pay In-App is not just a money-making trick but a behavior with serious risks for all involved parties.

Risks and Warnings
Risks and Warnings

7.1 For Miners: Consequences of Illicit Profiteering

Those who perform “hitting” face direct and long-term consequences:

7.2 For Cardholders: Self-Protection and Incident Handling

Cardholders are direct victims of financial loss. Note these signs and procedures:

7.3 For App Developers: Reputation and Revenue Damage

Businesses owning apps are also heavily affected by this issue:


7.4 Real People, Real Cases - When Black MMO Reaches International Courts

Many people in the Vietnamese Black MMO community still keep the mindset that “if I do it small, nobody will notice” or “Vietnamese authorities will not know enough to prosecute.” The international lawsuits below show a different reality: when the operation becomes large enough or touches the infrastructure of major technology corporations, you can be traced across borders - and your name, face, and address can be published publicly on Microsoft or Meta’s official blogs.


Case 1: Storm-1152 - Microsoft Sued 3 Vietnamese Individuals (December 2023)

This is the most typical case directly related to fake accounts - one of the foundational skill sets in Vietnamese Black MMO.

What happened:

On December 13, 2023, Microsoft announced on its official blog that it had submitted a criminal referral to U.S. law enforcement and obtained an order from a federal court in New York allowing it to seize the technical infrastructure of the cybercrime group known as Storm-1152.

Three individuals were publicly named, with photos:

Scale of operation:

Storm-1152 created and sold about 750 million fake Microsoft accounts (Outlook, Hotmail) used for cybercrime - spam, ransomware, and data theft - generating millions of dollars in illegal revenue. The group did not only sell accounts; it also built and sold CAPTCHA bypass tools and ran customer support professionally, like a legitimate technology company. Kevin Gosschalk, CEO of Arkose Labs (Microsoft’s investigation partner), observed that Storm-1152 “looked like a normal internet business” in how it operated.

How they were detected:

Microsoft cybersecurity specialists worked with Arkose Labs to purchase the group’s services, analyze behavior, trace server infrastructure, and identify real identities. The group’s accounts were found in multiple ransomware campaigns run by Octo Tempest since 2021, meaning Microsoft had monitored them for at least two years before taking legal action.

Lesson: When you become large enough to be a “service provider” for other cybercriminals, you are no longer just an anonymous Miner. You become a link in a criminal chain that can be traced from the other end.


Case 2: Meta Sued Ly Van Lam - Cloaking Ads Fraud (February 2026)

On February 27, 2026, Meta (the parent company of Facebook, Instagram, and WhatsApp) announced a lawsuit against Ly Van Lam, an individual in Vietnam, over large-scale scam advertising using cloaking techniques.

How it worked:

The cloaking technique that Ly Van Lam was accused of using follows a principle similar to spoofing in Pay In-App: when Meta’s review system scanned the ad, it saw a normal, compliant website. But when real users clicked, they were redirected to a fake Longchamp-branded website asking them to enter credit card information to “claim a survey gift.” After victims entered their information, their cards were charged unauthorized recurring fees - subscription fraud.

Consequences:

Meta sent cease-and-desist letters to 8 related marketing partners and also announced that in the first half of 2025, the platform removed more than 5.4 million violating pieces of content on Facebook and 14,000 on Instagram in Vietnam alone. More than 116,000 Facebook accounts and 28,000 Instagram accounts were suspended.

Notable point:

Longchamp (the impersonated brand) confirmed that it cooperated with Meta during the investigation and stated a “zero tolerance” policy. When more major brands join an investigation, the amount of evidence collected increases significantly.


Case 3: X (Twitter) Sued Vietnamese Individuals for Traffic Manipulation

Elon Musk’s social network X has also sued individuals in Vietnam for manipulating traffic, creating fake trends, and cheating engagement to earn money from the platform’s revenue-sharing program. This is an area many people in the Vietnamese Black MMO community are exploiting, and the legal risk around it is rising.


8.1 Vietnamese Law

Many Black MMO participants believe that “if I target foreigners and earn foreign money, Vietnamese law cannot touch me.” This belief is wrong. Vietnam’s Penal Code applies to acts committed on Vietnamese territory, regardless of where the victim is located.

Article 290 of the 2015 Penal Code (amended in 2017) - Using Computer Networks, Telecommunications Networks, or Electronic Devices to Appropriate Property

This is the legal provision that directly covers Pay In-App carding. Under Article 290, the following acts constitute crimes:

Penalty framework:

Damage levelPenalty
Under VND 20 million (or after administrative sanction)Non-custodial reform up to 3 years or imprisonment from 6 months to 3 years
VND 20 million to under VND 200 millionImprisonment from 2 to 7 years
VND 200 million to under VND 500 millionImprisonment from 7 to 15 years
VND 500 million or moreImprisonment from 12 to 20 years

Important note: Article 290 does not require “serious consequences” before prosecution (unlike some older laws). Once the act occurs, the crime can already be established.

Article 291 of the 2015 Penal Code - Illegally Collecting, Storing, Exchanging, Trading, or Publicizing Bank Account Information

Article 291 supplements Article 290 and directly targets Sellers in the supply chain - those who buy and sell Ci on Telegram or Darkweb Markets:

Decree 15/2020/ND-CP - Administrative Sanctions in Postal, Telecommunications, Radio Frequency, and IT Fields

For acts that have not reached the level of criminal prosecution, authorities can impose administrative penalties under Decree 15/2020 (amended by Decree 14/2022): fines from VND 10 to 20 million for violations related to illegal access and online identity spoofing.


8.2 International Law - Why Can “Taking Foreign Money” Still Lead to Lawsuits?

Computer Fraud and Abuse Act - CFAA (United States)

CFAA is the U.S. federal law most commonly used to prosecute cross-border cybercrime. You do not need to be on U.S. soil - if the act involves attacking or illegally accessing a computer system belonging to a U.S. company, CFAA can apply.

This is the legal basis Microsoft used against Storm-1152: three Vietnamese individuals allegedly accessed Microsoft’s systems (located in the U.S.) without authorization, so CFAA could apply. Penalties under CFAA can reach 10 years in prison for a first offense and 20 years for repeat offenses.

Computer Misuse Act 1990 - CMA (United Kingdom)

Similar to CFAA, but applied to systems belonging to UK companies or where the victim is in the UK. CMA provides:

GDPR (European Union) - General Data Protection Regulation

GDPR is not only a privacy law - it is also a basis for EU authorities to coordinate prosecution of acts involving theft of personal data of EU citizens, including credit card information. When Hackers collect Ci from EU cardholders, that violates GDPR. Administrative fines can reach EUR 20 million or 4% of global revenue for violating organizations, but for individuals, GDPR is often combined with national criminal laws to increase prosecutorial pressure.

A practical question in the community is: “If Microsoft sues in the U.S., how can they arrest someone in Vietnam?” The answer is Mutual Legal Assistance Treaty (MLAT) mechanisms. The U.S. and Vietnam have cooperation channels for investigating cross-border cybercrime. When the crime is large enough (as in Storm-1152), U.S. law enforcement can send an investigative assistance request to Vietnam’s Ministry of Public Security. This is why operational scale is decisive - no one uses MLAT to chase a small-time Miner, but at Storm-1152 scale, the situation changes.


9. Google Play and Apple App Store Detection Mechanisms - A Defensive View

9.1 Google Play Integrity API - The Latest Detection Generation

Since 2023, Google has replaced SafetyNet Attestation API with Play Integrity API - a much more comprehensive system for evaluating device trust and app runtime environments. Play Integrity API evaluates three layers:

Layer 1 - App Integrity: Verifies whether the running APK is the original version from Play Store and whether it has been repacked or injected.

Layer 2 - Device Integrity: This is the most important layer for Pay In-App. The system returns one of several verdicts:

Layer 3 - Account Integrity: Whether the Google account has a trustworthy activity history, age, and previously used devices.

Major payment apps call Play Integrity API before each transaction and reject processing if the verdict is below their allowed threshold. This is why Hide Root techniques (Magisk DenyList, Zygisk) constantly need updates to keep up with Google’s patches - it is an endless cat-and-mouse game, and Google has the infrastructure advantage.

9.2 Apple StoreKit and App Store Payment Security

The iOS ecosystem is significantly harder to exploit than Android because:

In practice, In-App fraud rates on iOS are significantly lower than on Android. This is also why most Tuts in the Vietnamese Black MMO community focus on Android.

9.3 Velocity Checks and Behavioral Analysis

Beyond device attestation, payment gateways (Stripe, Braintree, Adyen) and Google Pay itself run behavior analysis layers:

The most important point: Google and Apple do not need to catch every individual transaction. They analyze patterns over time. Small-time Miners may not be detected immediately, but accumulated history across devices, IPs, and accounts gradually builds a risk profile. Once the threshold is met, the whole cluster can be banned at once.


10. Cardholder Self-Protection and Detailed Chargeback Process

10.1 Early Detection - Signs Your Card Is Being Exploited

Fraudulent Pay In-App transactions often have these characteristics on statements:

SignExplanation
Google Play/Apple App Store transactions with small amounts (~0.1-2 USD)Miner is testing whether the card is still live (micro-transaction)
Multiple consecutive transactions within minutesMiner is “hitting” quickly before the card is locked
Transactions around midnight Vietnam time (early morning U.S./Europe time)U.S./EU cards are being exploited from Vietnam
Transactions from foreign games or livestream apps you have never usedLiquidation through donations/coins
Recurring subscription fees from unfamiliar servicesSubscription fraud after card information has been resold

10.2 Chargeback Process - Step by Step

Step 1: Lock the card immediately Call your bank’s 24/7 hotline to request a card lock and new card issuance. This is the top priority, even before further investigation.

Step 2: Save evidence Take screenshots of all suspicious transactions in the banking app, including time and amount. Save transaction confirmation emails if any.

Step 3: Submit a chargeback request Contact the issuing bank (not the acquiring bank) to request a dispute investigation. Information to provide:

Step 4: Timeline and outcome

Step 5: Additional reporting Besides the bank, cardholders should report to:

10.3 Long-Term Prevention


11. Conclusion

Pay In-App in the Black MMO world is essentially a risky form of illicit profiteering based on the unauthorized exploitation of others’ payment card information.

While “Miners” may use sophisticated techniques like device spoofing or SOCKS5 to bypass controls, this behavior not only causes great damage to cardholders and app developers but also leads to serious legal consequences for the perpetrators themselves.

To protect yourself in the digital environment, users are advised to always be vigilant, strictly protect credit card information, and prioritize using two-factor authentication methods (3D Secure/OTP) for all online transactions. Understanding payment error codes and virtual money flow mechanisms is also a way for users to recognize fraud signs early.

Thank you for patiently reading to the end of this relatively long article. Hope the information above has provided you with a comprehensive and useful look at the hidden corners of Pay In-App. Wish you a great day and always stay safe in cyberspace!


Frequently Asked Questions (Q&A)

Q: Why don’t apps block this loophole completely?

A: If apps tightened security excessively, real users would face many difficulties and inconveniences when paying. Therefore, apps usually accept a certain rate of risk and only tighten controls when damage becomes too great.

Q: Are Prepaid cards safer than Credit cards?

A: In reality, Miners rarely exploit Prepaid cards because the probability of a high balance is lower compared to Credit and Debit cards. However, any card type needs absolute Ci security.

Q: What should I do if I see error code OR-CCSEH-26 while making a purchase myself?

A: This error code usually indicates that your card balance is insufficient. Please check your bank account or top up before trying again.

Q: Can people doing Black MMO in Vietnam be arrested if they only do it on a small scale?

A: In practice, Vietnamese authorities currently prioritize cases with large scale, clear damage, and specific reports. Small-scale Miners are rarely the first investigative priority. However, the risk comes from another direction: foreign corporations (Google, Apple, Microsoft, Meta) have automated pattern analysis systems, and when they detect fraud clusters linked to Vietnam, they can send cooperation requests to the Ministry of Public Security through MLAT mechanisms. At that point, you are no longer “small-scale” in the investigation file.

Q: How can Microsoft and Meta know the real identities of operators?

A: Because they do not need to catch someone on the first transaction. They collect data over months and years: IP logs, device fingerprints, payment trails, tutorial YouTube channels (such as Duong Dinh Tu’s), Telegram accounts selling Ci, and wallet addresses receiving money. Once there is enough evidence, one lawsuit can expose everything. Good OPSEC can slow this process down, but it cannot stop it completely.

Q: If I only buy Ci and do not hack it myself, can I still be prosecuted?

A: Yes. Article 291 of the 2015 Penal Code clearly states that storing and trading bank account information illegally is also a crime - you do not need to be the person who directly stole it. People who buy Ci on Telegram or Darkweb Markets fall within the scope of Article 291.

Q: Do detection bypass techniques get patched? Do Tuts “die”?

A: Yes, continuously. Google Play Integrity API replacing SafetyNet is a typical example - old Tuts based on SafetyNet became ineffective. Apple App Attest is also updated with each major iOS version. Every time Google or Apple pushes a security patch, bypass tools must update to keep up. Tuts have a shelf life, and that shelf life is getting shorter as platforms invest more in ML-based fraud detection instead of rule-based detection.

This article was researched and written from the perspective of a fullstack developer with more than 3 years of experience building payment systems, integrating payment gateways (SePay, VNPay, Stripe), and developing mobile applications. Its purpose is to provide a comprehensive technical view of operating mechanisms, legal risks, and defensive mechanisms - not practical instructions.

The case studies are drawn from mainstream press sources (VnExpress, Dantri, Tuoi Tre, and the official blogs of Microsoft and Meta). The legal provisions are cited from current Vietnamese legal documents.

Author: Nguyễn Hữu Khải - Fullstack Developer, khaizinam


Share this post:

Related Posts

Use ChatGPT, Gemini, and Codex for Long SEO Content

Use Claude, ChatGPT, Gemini, and Codex to write long SEO content: intent research, outlines, section writing, E-E-A-T audits, and internal links.

Cheap AI Accounts: The Dark Side of MMO Reselling and 4 Hidden Risks You Need to Know (2026)

This article provides a technical analysis of the cheap AI account market in Vietnam, helping users understand the origins, hidden risks, and safer...

Ninety Thousand Acres: How I Turned the Tables on a 1 vs 4 Siege With Pure Psychology

Surrounded by 4 stronger kingdoms in Ninety Thousand Acres? Here's how I used the truce window, the daily attack hours, and pure psychological warfare to...

In Depth Review of Ninety Thousand Acres

Ninety Thousand Acres (Chinese: 九萬畝) is a mobile simulation management and strategy (SLG) game published by DH-Publisher, heavily inspired by the Three...

IT Job Benefits Beyond Salary - What Freshers Always Miss

Salary is just one part of total compensation. Here are the IT job benefits freshers consistently overlook when evaluating an offer - and how to ask without...

Outsource vs Product Company for Junior Devs: Which Should You Choose?

Outsource companies pay 20–35% less but are much easier to get into - product companies offer more depth but set a higher bar. A real comparison to help you...

Gothic Sketch AI Prompt: Turn Your Photo into Sketchbook Art

A complete gothic sketch AI prompt to transform your portrait into dark sketchbook art - copy, paste, done. Works on ChatGPT, Midjourney, and Stable...

Rejecting an IT Job Offer: 5 Red Flags Freshers Must Know

5 red flags in IT job offers every fresher and junior must recognize. Knowing when to say no protects you from wasting 6–12 months in the wrong environment.

Will AI Replace Developers in Vietnam? What the 2026 IT Market Data Shows

Will AI replace developers in Vietnam? A data-backed look at Vietnam's 2026 IT talent market, AI adoption, hiring plans, and the skills foreign companies...

I Ditched Antigravity IDE and Went Back to VSCode + Codex

After Antigravity 2.0 silently tanked my IDE's performance to force an upgrade, I uninstalled it. Here's what actually happened - and why Gemini's...


Previous Post
JWT Interview Questions and Answers (2026)
Next Post
Use ChatGPT, Gemini, and Codex for Long SEO Content