Malware News 'One install, and the phone is no longer yours' — NordVPN warns of fake Ryanair, Emirates, Qatar Airways apps used to spread malware

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
The VPN provider found that one fake app install can give criminals full remote access to your phone

  • NordVPN found a malware campaign impersonating 65 brands
  • It tricks victims into clicking on messages requesting urgent action
  • If you use an Android phone, it’s worth checking your apps
Summer is still in full swing with many people out enjoying their holidays. Unfortunately, cybercriminals never stop trying to steal money by tricking people into believing they are on trustworthy websites or using legitimate apps — especially when our attention is more likely to wander.

That’s what NordVPN, the pinnacle of the best VPNs, recently investigated, issuing an alert urging caution over a widespread and sophisticated malware campaign targeting Android users through highly convincing phishing schemes.

The malware is posing as over 65 well-known brands, including Ryanair, Emirates, and Qatar Airways, as well as tax authorities, registry offices, and social security systems that lure you into downloading their apps.

The dangerous trojan tracks your messages and logins, spies on you through your camera, records your voice, and bypasses two-factor authentication before ultimately draining your bank account.

The campaign has targeted users in Southeast Asia, Latin America, and Africa.
What the research found
NordVPN spent the last 12 months investigating the malware campaign — including its infrastructure and impersonation targets — analysing malware clusters and mapping more than 100 domains linked to the campaign.

It discovered that the campaign tricks users into installing an app that grants full access to their Android phones or computers by impersonating highly trustworthy companies — brands people are accustomed to providing their personal data without questioning it.

Victims are lured by a variety of requests via SMS, WhatsApp, or social media that look totally innocuous, like a job opening at an airline, a cheap flight, or a tax refund.

Once installed, the Trojan runs quietly in the background and stays active even if the phone is restarted, accessing your messages and call logs, capturing the screen, recording audio, and accessing the camera.

Attackers can even log into the victim's banking app and approve transactions themselves by using SMS interception to steal your money, as most banks implement two-factor authentication through one-time codes sent by text.
Marijus Briedis, chief technology officer at NordVPN, says: "One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside."

Trusted brands are often the most spoofed brands in phishing scams, alongside other malware 'tricks' to gain trust, such as multi-platform PR campaigns promoting malware as legitimate software, or even Chrome extensions impersonating VPNs.

However, unlike many opportunistic phishing attempts, these attacks have been particularly hard to spot, featuring extremely accurate replicas of legitimate websites, meticulously copied and professionally translated.
Briedis advises Android users to be very careful not to install apps from links received via text message. "Real airlines, banks and government bodies distribute apps through Google Play, not SMS or WhatsApp," he stresses.

As with other AI impersonating scams, users should treat any urgent request as a warning sign: whenever there is mention of a refund or an account being blocked, check the source carefully before clicking on anything or taking any action.

Checking that a website is legitimate and does not operate from domains ending in .cc, .lol, .xyz, .mom, or .pw will be a clear safety indicator.

Furthermore, do not rely on 'the padlock icon': an HTTPS connection merely indicates that the connection is encrypted, not that the site is genuine.

If you suspect that a suspicious app is already on your phone, disconnect your phone from the internet, uninstall the app, change your password from another device, and contact your bank: this will ensure you’re back in the clear.

And remember that if even the current UK Prime Minister can be a scam target, perhaps you should remain vigilant too.
 
Hi Brownie, this is a credible and dangerous Android sideloading campaign, although the headline compresses several steps into “one install.” NordVPN’s report says its researchers examined 10 APK samples associated with more than 65 impersonated organisations and over 100 domains. The samples requested access capable of reading SMS, recording audio, using the camera and capturing the screen.

The important distinction is the attack chain:

  1. The victim receives the message and visits a counterfeit site.
  2. An APK is downloaded outside Google Play.
  3. Android is permitted to install apps from that source.
  4. The app is installed and sensitive permissions are granted.

Merely receiving the message—or even visiting the page—is not an infection by the route described here. “One install” really means “sideload the APK and approve the access it asks for.” Once that has happened, however, the phone and accounts used on it should indeed be considered potentially compromised.

A few claims in the article need tightening:

  • The samples have the capability to steal data and facilitate fraudulent transactions; that does not establish that every installation inevitably ends with an emptied bank account.
  • Reading SMS can defeat SMS-based one-time codes, not magically bypass every kind of two-factor authentication.
  • Avoiding .cc, .lol, .xyz, .mom and .pw is not a “clear safety indicator.” Those were clues associated with this campaign. Criminals can use .com, while legitimate sites can use less common endings.
  • Legitimate organisations might send a link to their verified Google Play listing. The major warning is a message directing someone to install an APK directly.
  • Uninstalling the app does not guarantee that everything is clear. It cannot undo credentials, session tokens or information already stolen.

If someone actually installed one of these apps, the sensible response is to disconnect the phone, stop using it for banking, and contact the bank from a trusted device. Secure the primary email/Google and financial accounts, revoke unfamiliar sessions, review MFA and recovery settings, and inspect transactions. Google Play Protect can check sideloaded applications, but a clean result is not proof that no compromise occurred.

Where SMS, Accessibility, device-administrator, screen-capture or similar powerful access was granted, a carefully prepared factory reset is usually the safer end state. Anyone in that position should open a case with MalwareTips’ Malware Removal Assistance team for individual guidance rather than relying on “uninstall and hope.”

And despite the branding, a VPN is not the remedy here. Encryption cannot make a deliberately installed trojan behave itself.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top