Tech experts say thieves are using fake websites made to look like legitimate brands to access personal data and bank accounts. NordVPN's threat Intelligence research team has identified a malware campaign distributing a virus by impersonating more than 65 well-known brands.
The campaign impersonates airlines including Ryanair, Emirates, and Qatar Airways, as well as tax authorities, civil registries, and social security systems. Victims receive a message over SMS, WhatsApp, or social media with an urgent and believable pretext: a job opening at an airline, a pending tax refund, an ID renewal notice, a pension verification request, or a heavily discounted flight.
The link leads to a website that looks exactly like the impersonated organisation and prompts the victim to install an Android app. What makes this campaign dangerous is how ordinary the bait is. A tax refund or a flight deal does not feel like a threat, it feels like good news, said Marijus Briedis, chief technology officer at NordVPN. One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside.
Once installed, the trojan runs quietly in the background and stays active even after the phone is restarted. It requests permissions that no airline or government app would ever need: reading SMS messages, contacts, and call logs, capturing the screen, recording audio, and activating the camera.
Because most banks send one-time codes by text, the malware effectively neutralises two-factor authentication by letting hackers see your text messages. Attackers can log into the victim's banking app and approve the transaction themselves.
The campaign deliberately targets high-trust sectors. Every fraudulent page is professionally localised, so a victim in Manila, Mexico City, Jakarta, or Sydney sees a site in their own language. The operation has been active since at least August 2025 and rotates its infrastructure constantly.
Domain names are registered on disposable extensions like .cc, .lol, .xyz, and .mom and new ones appear as soon as old ones are abandoned. NordVPN's analysts identified more than 100 domains linked to the campaign.
How to stay safe
Marijus Briedis advises Android users to keep these rules in mind:
Never install an app from a link received in a message. Real airlines, banks, and government bodies distribute apps through Google Play, not SMS or WhatsApp.
Treat urgency as a warning sign. Any message demanding immediate action because of an expiring prize, a refund deadline, or an account lock, deserves suspicion, not a tap.
Check the web address. Legitimate government and corporate services do not operate from domains ending in .cc, .lol, .xyz, .mom, or .pw.
Do not trust the padlock. An HTTPS connection only means the connection is encrypted, not that the site is genuine.
If you have installed a suspicious app, disconnect the phone from the internet, uninstall it, change your passwords from a different device, and contact your bank.