0

African Airlines, Tax Authorities, and Retailers Weaponized in Global Android Banking-Trojan Campaign

Imagine handing over the keys to your digital life—and your bank account—every time you download a seemingly legitimate app. That is the stark reality for victims of a sprawling Android malware campaign. According to NordVPN’s Threat Intelligence team, this malware has been actively impersonating more than 65 trusted global brands since August 2025. This isn’t simple credential theft; it is a full-scale device hijack. The banking trojan doesn’t just steal login details. It intercepts SMS-based two-factor authentication, and livestreams your screen in real time. The intruder silently seizes control of your microphone and camera. These infections are already confirmed across Asia, Africa, Australia, the Middle East, Latin America, and Europ. Already over six-months and-counting, no region is immune to the growing sophistication of mobile device takeovers.

Highlights

  • NordVPN’s Threat Intelligence team uncovers a banking trojan impersonating over 65 trusted brands
  • One fake app install gives criminals full remote access to your phone, your bank account, and your camera

NordVPN’s Threat Intelligence research team has identified a widespread Android malware campaign distributing a Remote Access Trojan (RAT) and banking trojan by impersonating more than 65 well-known brands.

RELATED:  Kaspersky uncovers new SparkCat malware variant evading App Store and Google Play defences

The campaign impersonates airlines including Ethiopian Airlines, South African Airways, and Kenya Airways, as well as government services such as South Africa’s revenue service SARS, Nigeria’s Corporate Affairs Commission, and major African brands like Takealot, DStv, and Bank of Africa.

ImageImage
Impersonated website domains takedalot[.]cc and flysaa[.]wpigo[.]cc.
Victims receive a message over SMS, WhatsApp, or social media with an urgent and believable pretext: a job opening at an airline, a pending tax refund, an ID renewal notice, a pension verification request, or a heavily discounted flight. The link leads to a professionally translated website that looks exactly like the impersonated organization and prompts the victim to install an Android app.
“What makes this campaign dangerous is how ordinary the bait is. A tax refund or a flight deal does not feel like a threat, it feels like good news. One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside,” says Marijus Briedis, chief technology officer at NordVPN.

An app that watches, listens, and waits

Once installed, the trojan runs quietly in the background and stays active even after the phone is restarted. It requests permissions that no airline or government app would ever need: reading SMS messages, contacts, and call logs, capturing the screen, recording audio, and activating the camera.
The most damaging capability is SMS interception. Because most banks send one-time codes by text, the malware effectively neutralizes two-factor authentication. Attackers can log into the victim’s banking app and approve the transaction themselves.
The campaign deliberately targets high-trust sectors. Tax offices, social security systems, civil registries, and healthcare providers are institutions where people are used to handing over personal data without question. Every fraudulent page is professionally localized, so a victim in Manila, Mexico City, Jakarta, or Sydney sees a site in their own language.
The operation has been active since at least August 2025 and rotates its infrastructure constantly. Domain names are registered on disposable extensions like .cc, .lol, .xyz, and .mom, almost all abuse Cloudflare as a shield, and new ones appear as soon as old ones are abandoned. NordVPN’s analysts identified more than 100 domains linked to the campaign.

How to stay safe

Marijus Briedis advises Android users to keep these rules in mind:
  • Never install an app from a link received in a message. Real airlines, banks, and government bodies distribute apps through Google Play, not SMS or WhatsApp.
  • Treat urgency as a warning sign. Any message demanding immediate action because of an expiring prize, a refund deadline, or an account lock, deserves suspicion, not a tap.
  • Check the web address. Legitimate government and corporate services do not operate from domains ending in .cc, .lol, .xyz, .mom, or .pw.
  • Do not trust the padlock. An HTTPS connection only means the connection is encrypted, not that the site is genuine.
  • If you have installed a suspicious app, disconnect the phone from the internet, uninstall it, change your passwords from a different device, and contact your bank.

Methodology

NordVPN’s Threat Intelligence team analyzed 10 malware samples, grouping them into seven clusters based on signing certificates. It mapped more than 100 domains used by the campaign since August 2025. Analysts reviewed the permissions requested by each sample. They extracted internal code components, and examined domain registration and hosting patterns. Thence, they reconstructed the campaign’s infrastructure and impersonation targets.

More in News

You may also like