NordVPN's Threat Intelligence team has identified a widespread Android malware campaign distributing a remote access trojan and banking trojan by impersonating more than 65 well-known brands, the company said. The campaign impersonates airlines including Philippine Airlines, Malaysia Airlines and Air India, as well as government services such as Indonesia's tax authority Coretax, the Philippines' Social Security System, Thailand's SSO pension system, and Vietnam's social insurance agency and Ministry of Health, according to NordVPN.
Victims receive a message over SMS, WhatsApp or social media with an urgent pretext, the company said, such as a job opening at an airline, a pending tax refund, an ID renewal notice, a pension verification request or a discounted flight. The link leads to a professionally translated website that closely mimics the impersonated organization and prompts the victim to install an Android app, according to NordVPN.
"What makes this campaign dangerous is how ordinary the bait is. A tax refund or a flight deal does not feel like a threat, it feels like good news," said Marijus Briedis, chief technology officer at NordVPN. "One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside."
Once installed, the trojan runs in the background and stays active even after the phone restarts, NordVPN said. It requests permissions no legitimate airline or government app would need, according to the company, including reading SMS messages, contacts and call logs, capturing the screen, recording audio and activating the camera.
The most damaging capability is SMS interception, NordVPN said, since most banks send one-time verification codes by text — a mechanism the malware can neutralize entirely, allowing attackers to log into a victim's banking app and approve transactions themselves.
The campaign specifically targets high-trust institutions, according to NordVPN, including tax offices, social security systems, civil registries and healthcare providers, sectors where people are accustomed to sharing personal data without hesitation. Every fraudulent page is professionally localized, the company said, so victims across different regions see the scam in their own language.
More than 100 domains identified since August 2025
The operation has been active since at least August 2025 and rotates its infrastructure constantly, NordVPN said. Domain names are registered on disposable extensions such as .cc, .lol, .xyz and .mom, according to the company, with most abusing Cloudflare as a shield and new domains appearing as older ones are abandoned. NordVPN's analysts identified more than 100 domains linked to the campaign.
The company said its research team analyzed 10 malware samples, grouping them into seven clusters based on signing certificates, and mapped the domains through a review of app permissions, internal code components, and domain registration and hosting patterns.
NordVPN recommended that Android users never install an app from a link received in a message, since legitimate airlines, banks and government bodies distribute apps only through Google Play. The company advised treating urgency as a warning sign, checking web addresses for suspicious domain extensions, and not assuming a padlock icon or HTTPS connection confirms a site's legitimacy. Users who have installed a suspicious app should disconnect the phone from the internet, uninstall the app, change passwords from a separate device, and contact their bank, according to NordVPN.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




