NordVPN’s threat research team has exposed a sprawling Android malware campaign built on fake versions of well-known airline and government apps, including Ryanair, Emirates and Qatar Airways, designed to take over a victim’s phone completely rather than just steal a password. The company’s CTO put it bluntly: “One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside.”
What NordVPN found
The investigation ran for roughly 12 months and analyzed more than 100 domains linked to the operation. The campaign impersonates 65 well-known organizations in total, spanning airlines, tax authorities and social security systems, primarily targeting users in Southeast Asia, Latin America and Africa. Victims are lured through convincing phishing messages, typically sent via SMS or WhatsApp, urging them to install what looks like an official app from a trusted, recognizable brand.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
What the malware actually does once installed
Once a victim installs the fake app, it runs quietly in the background and gives the attacker a disturbing amount of access: reading messages and call logs, capturing screenshots, recording audio, accessing the camera, and critically, intercepting SMS codes used for two-factor authentication. That last capability is what turns this from an invasive privacy breach into direct financial theft: with two-factor codes intercepted in real time, attackers can approve unauthorized banking transactions and drain accounts from the inside, using the exact verification step banking apps rely on to prove a transaction is really coming from the account holder. Screen and audio capture on top of that means the attacker can watch a victim log into other, unrelated accounts too, extending the damage well past whichever bank prompted the original install.
Why airlines and government apps specifically
Airline apps and government service apps share a useful trait for scammers: they’re both trusted, high-urgency categories people don’t hesitate to interact with. A message claiming a flight change, a tax issue or a benefits update tends to get opened and acted on quickly, without the same suspicion a random link might raise. NordVPN’s research notes the campaign leans specifically on this urgency, framing malicious download links as time-sensitive official communications rather than routine offers.
How to protect yourself
NordVPN’s guidance is straightforward and worth following regardless of whether you think you’ve been targeted specifically. Avoid installing any app from a link sent through SMS or WhatsApp, even if the message looks official; legitimate airlines and government agencies distribute their apps through Google Play or the Apple App Store, not direct download links. Treat any message demanding urgent action, a flight change, a tax deadline, a benefits suspension, as a warning sign rather than a reason to act fast. Check the actual domain in any link before tapping it; the campaign used suspicious top-level domains like .cc, .lol, .xyz, .mom and .pw rather than the real, official domains of the brands being impersonated. And remember that an HTTPS padlock icon in your browser confirms an encrypted connection, not that the site itself is legitimate; scam sites can and do use HTTPS just as easily as real ones.
If you think you’ve already installed a fake app
Disconnect your device from the internet immediately, which cuts off the attacker’s ability to keep sending commands or extracting data. Uninstall the app as soon as you’re able to. Change your passwords, starting with banking and email, from a different, uncompromised device rather than the one you suspect is infected. Contact your bank directly to flag potential unauthorized access and watch your accounts closely for the following weeks, since attackers sometimes wait before acting on stolen access to avoid drawing immediate attention. A factory reset of the affected device, once you’ve backed up anything essential through a clean, verified method, is the most thorough way to be certain nothing malicious survives on the phone itself.
Where a VPN fits, and where it doesn’t
It’s worth being precise here: a VPN encrypts your connection and hides your IP address, but it does not prevent you from installing a malicious app, and it can’t undo the access that app grants once it’s running on your device. What actually stops this specific threat is the behavioral advice above, official app stores only, skepticism toward urgent unsolicited messages, and checking domains before clicking. A VPN is a complementary layer for your broader security, not a defense against a malicious app you’ve already installed yourself.
Who’s most exposed
The geographic targeting, Southeast Asia, Latin America and Africa, isn’t random. NordVPN’s research points to regions where Android holds a larger share of the smartphone market than iOS, where app-store enforcement against sideloaded or third-party app sources can be less consistent, and where SMS and WhatsApp remain the dominant channels for both legitimate customer communication and, as this campaign shows, fraud. None of that makes users elsewhere immune. The same tactics work anywhere someone is willing to install an app from a text message link instead of a verified store, which is a habit worth breaking regardless of where you live.
Why this campaign stayed under the radar for so long
Twelve months of investigation and over 100 linked domains is a large operation, and a big part of what let it run that long is the sheer number of throwaway domains involved. When one fake site gets flagged and taken down, the campaign can simply redirect victims to another, freshly registered domain, often with a nearly identical design. This kind of infrastructure churn is exactly why individual domain blocklists lag behind campaigns like this one, and why behavioral habits, checking the source of a link rather than trusting the page it leads to, hold up better than trying to keep a personal blocklist current.
The bigger pattern
This campaign fits a broader trend security researchers have flagged repeatedly through 2026: attackers increasingly target the two-factor authentication step directly, rather than trying to steal a password alone, since modern banking apps have made passwords alone insufficient for most fraud. A malware app that can read SMS codes in real time effectively neutralizes the extra protection two-factor authentication is supposed to add, which is exactly why this kind of full-device-takeover malware is more dangerous than older, simpler phishing pages that only captured login credentials. A stolen password alone is often useless against an account with two-factor authentication turned on; a phone that’s been fully compromised gives an attacker both halves of that equation at once.
This is a phone-takeover threat, not a browsing-privacy issue, so the fix is behavioral: official app stores only, skepticism toward urgent SMS and WhatsApp links, and checking domains before you tap anything. Pair that with a VPN like NordVPN for your broader connection security, but don't mistake it for protection against a malicious app you've already installed.
Keep reading: Does a VPN Protect You From Phishing? What It Can (and Can’t) Do and VPN vs Antivirus: Different Jobs, Same Computer. Do You Need Both?.