'One install, and the phone is no longer yours' — NordVPN warns of fake Ryanair, Emirates, Qatar Airways apps used to spread malware
NordVPN urges caution online over a banking Trojan masquerading as more than 65 reputable brands. Here’s how to protect your phone.
NordVPN has uncovered a malware campaign that impersonates over 65 well-known brands, including Ryanair, Emirates, and Qatar Airways. The malicious apps are designed to trick Android users into downloading them, often through seemingly innocuous messages or requests via SMS, WhatsApp, or social media. Once installed, the malware grants complete access to the victim's device, monitoring messages, logs, and even the device's camera and microphone.
Most alarmingly, it can bypass two-factor authentication to empty bank accounts. The campaign has primarily targeted users in Southeast Asia, Latin America, and Africa. The malware's success stems from its ability to create highly convincing replicas of legitimate websites and apps, often using professional translation to appear authentic.
NordVPN advises Android users to avoid installing apps from links received via text message, as real airlines, banks, and government bodies distribute apps through Google Play. Users should treat any urgent requests, especially those involving refunds or account blocks, as potential scams and verify the source before taking any action.
Lastly, do not rely solely on the HTTPS or padlock icon, as the presence of encryption does not guarantee the site's legitimacy.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.