| [ Web Proxy ] |
| Viewing: https://www.examinerlive.co.uk/news/uk-world-news/ryanair-qatar-emirates-apps-being-34482916 | [Back] [Original] |
Tech experts say thieves are using fake websites made to look like legitimate brands to access personal data and bank accounts. NordVPN's threat Intelligence research team has identified a malware campaign distributing a virus by impersonating more than 65 well-known brands.
The campaign impersonates airlines including Ryanair, Emirates, and Qatar Airways, as well as tax authorities, civil registries, and social security systems. Victims receive a message over SMS, WhatsApp, or social media with an urgent and believable pretext: a job opening at an airline, a pending tax refund, an ID renewal notice, a pension verification request, or a heavily discounted flight.
The link leads to a website that looks exactly like the impersonated organisation and prompts the victim to install an Android app. What makes this campaign dangerous is how ordinary the bait is. A tax refund or a flight deal does not feel like a threat, it feels like good news, said Marijus Briedis, chief technology officer at NordVPN. One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside.
Once installed, the trojan runs quietly in the background and stays active even after the phone is restarted. It requests permissions that no airline or government app would ever need: reading SMS messages, contacts, and call logs, capturing the screen, recording audio, and activating the camera.
Because most banks send one-time codes by text, the malware effectively neutralises two-factor authentication by letting hackers see your text messages. Attackers can log into the victim's banking app and approve the transaction themselves.
The campaign deliberately targets high-trust sectors. Every fraudulent page is professionally localised, so a victim in Manila, Mexico City, Jakarta, or Sydney sees a site in their own language. The operation has been active since at least August 2025 and rotates its infrastructure constantly.
Domain names are registered on disposable extensions like .cc, .lol, .xyz, and .mom and new ones appear as soon as old ones are abandoned. NordVPN's analysts identified more than 100 domains linked to the campaign.
Marijus Briedis advises Android users to keep these rules in mind:
Choose Yorkshire Live as a 'Preferred Source' on Google News for quick access to the news you value.
[Google Preferred Source Badge]At Reach and across our entities we and our partners use information collected through cookies and other identifiers from your device to improve experience on our site, analyse how it is used and to show personalised advertising. You can opt out of the sale or sharing of your data, at any time clicking the "Do Not Sell or Share my Data" button at the bottom of the webpage. Please note that your preferences are browser specific. Use of our website and any of our services represents your acceptance of the use of cookies and consent to the practices described in our Privacy Notice and Terms and Conditions.
Accept| Web Proxy Viewer | New URL | Original Page |