Security researchers have lifted the lid on an ongoing Android malware campaign active in Australia, posing as several trusted and well-known brands to spread a Remote Access Trojan (RAT) designed, among other things, to steal banking information.
According to NordVPN’s threat intelligence team, the campaign is circulating via text messages, WhatsApp, and social media, impersonating brands such as supermarket giant Woolworths and several airlines, including Emirates, Qatar Airways, and Air India.
The campaign has also posed as social security systems and tax authorities and is active across Asia, Africa, the Middle East, Latin America, and Europe.
“What makes this campaign dangerous is how ordinary the bait is. A tax refund or a flight deal does not feel like a threat; it feels like good news,” Marijus Briedis, chief technology officer at NordVPN, said in a statement.
“One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside.”
The RAT, once installed, runs in the background and remains active even after restarting a device. It may appear to be a legitimate app, but it requests several unusual permissions, such as being able to access SMSes and contacts, call logs, and the device’s camera and audio.
Being able to access text messages lets the RAT intercept one-time codes sent by banks, essentially making two-factor authentication not only useless, but turning it into a way for a malicious actor to directly access the bank accounts of their victims.
The campaign has been active since August 2025 and uses rotating infrastructure, domain names registered on disposable extensions such as .cc and .lol, and takes advantage of Cloudflare “as a shield”. NordVPN has observed more than 100 discrete domains linked to the campaign.
Briedis recommends the following steps to stay safe:
- Never install an app from a link in a message. Download apps directly from official app stores or the organisation’s website.
- Treat urgent messages as a red flag, especially those demanding immediate action over prizes, refunds, or account closures.
- Check the web address carefully. Be wary of unfamiliar or unusual domains, particularly those commonly used in scams.
- Don’t trust the padlock icon. HTTPS encrypts your connection, but does not prove a website is legitimate.
- If you install a suspicious app, disconnect the phone from the internet, uninstall it, change your passwords from a different device and contact your bank.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.