NordVPN Identified Android Malware Impersonating Brands

A wide-reaching malware campaign targeted users of over 65 major organizations across Asia since August 2025.

Updated on Sept. 21, 2026 in Cybersecurity

Bold flat-color editorial illustration featuring an abstract metallic microchip substrate and filaments, representing complex digital security threats.
A widespread Android malware operation has been impersonating over 65 major organizations since August 2025 to intercept SMS verification codes for unauthorized banking access. AI Illustration. Upload story photo >

Live Poll

Do you trust your ability to identify and avoid fraudulent apps on your mobile device?

Analysts discovered an Android malware operation that has been active since August 2025, using fake websites to steal sensitive data. The campaign impersonates more than 65 brands and government services to intercept SMS codes for unauthorized banking access.

Why it matters

By impersonating high-trust government and travel institutions, attackers exploit user confidence to gain broad access to personal data. This tactic allows the malware to bypass security by intercepting verification codes that authenticate illicit transactions.

The campaign uses 100 distinct domains registered with extensions like .cc and .xyz to host fake Android applications. These samples request invasive permissions, including access to contacts, call logs, and SMS messaging capabilities.

The players

NordVPN

This cybersecurity company provides privacy services and conducts ongoing research into global digital threats and malware campaigns.

The details

Victims receive deceptive messages via SMS or WhatsApp that direct them to websites mimicking official portals for entities like Philippine Airlines or Vietnam's Ministry of Health. Once installed, the malware operates in the background, persisting even after a device is restarted to maintain continuous access.

Timeline

  1. The campaign has been active since August 2025.

  2. NordVPN published its analysis on September 21, 2026.

The Tech Race

This campaign follows a pattern set by Android banking trojans that leverage SMS interception to bypass two-factor authentication. It highlights the escalating arms race between security analysts and attackers who increasingly use disposable domain infrastructure to evade detection.

Users can protect themselves by avoiding links in unsolicited messages and only downloading applications from official, verified app stores. Granting permissions to unknown apps allows attackers to record audio, view camera feeds, and intercept private financial communications.

The takeaway

Maintaining strict skepticism toward unsolicited messages is essential, as attackers constantly evolve their ability to mimic trusted brand interfaces. Always review the requested permissions of any new application to ensure it does not require unnecessary access to sensitive device functions.

Further reading

For broader trends in digital safety, visit the Cybersecurity section.

Source note: This article includes information reported by Facebook.

Live Poll

Do you trust your ability to identify and avoid fraudulent apps on your mobile device?