'One install, and the phone is no longer yours' — NordVPN warns of fake Ryanair, Emirates, Qatar Airways apps used to spread malware
The VPN provider found that one fake app install can give criminals full remote access to your phone
- NordVPN found a malware campaign impersonating 65 brands
- It tricks victims into clicking on messages requesting urgent action
- If you use an Android phone, it’s worth checking your apps
Summer is still in full swing with many people out enjoying their holidays. Unfortunately, cybercriminals never stop trying to steal money by tricking people into believing they are on trustworthy websites or using legitimate apps — especially when our attention is more likely to wander.
That’s what NordVPN, the pinnacle of the best VPNs, recently investigated, issuing an alert urging caution over a widespread and sophisticated malware campaign targeting Android users through highly convincing phishing schemes.
The malware is posing as over 65 well-known brands, including Ryanair, Emirates, and Qatar Airways, as well as tax authorities, registry offices, and social security systems that lure you into downloading their apps.
The dangerous trojan tracks your messages and logins, spies on you through your camera, records your voice, and bypasses two-factor authentication before ultimately draining your bank account.
The campaign has targeted users in Southeast Asia, Latin America, and Africa.
NordVPN – the best VPN overall
NordVPN came out on top in our 2026 round of VPN tests. We think it's the best VPN for most people. We’re confident that virtually anyone can sign up for NordVPN and get what they need from it. It’s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.
Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee.
What the research found
NordVPN spent the last 12 months investigating the malware campaign — including its infrastructure and impersonation targets — analysing malware clusters and mapping more than 100 domains linked to the campaign.
It discovered that the campaign tricks users into installing an app that grants full access to their Android phones or computers by impersonating highly trustworthy companies — brands people are accustomed to providing their personal data without questioning it.
Victims are lured by a variety of requests via SMS, WhatsApp, or social media that look totally innocuous, like a job opening at an airline, a cheap flight, or a tax refund.
Once installed, the Trojan runs quietly in the background and stays active even if the phone is restarted, accessing your messages and call logs, capturing the screen, recording audio, and accessing the camera.
Attackers can even log into the victim's banking app and approve transactions themselves by using SMS interception to steal your money, as most banks implement two-factor authentication through one-time codes sent by text.
Marijus Briedis, chief technology officer at NordVPN, says: "One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside."
Trusted brands are often the most spoofed brands in phishing scams, alongside other malware 'tricks' to gain trust, such as multi-platform PR campaigns promoting malware as legitimate software, or even Chrome extensions impersonating VPNs.
However, unlike many opportunistic phishing attempts, these attacks have been particularly hard to spot, featuring extremely accurate replicas of legitimate websites, meticulously copied and professionally translated.
How to stay safe
Briedis advises Android users to be very careful not to install apps from links received via text message. "Real airlines, banks and government bodies distribute apps through Google Play, not SMS or WhatsApp," he stresses.
As with other AI impersonating scams, users should treat any urgent request as a warning sign: whenever there is mention of a refund or an account being blocked, check the source carefully before clicking on anything or taking any action.
Checking that a website is legitimate and does not operate from domains ending in .cc, .lol, .xyz, .mom, or .pw will be a clear safety indicator.
Furthermore, do not rely on 'the padlock icon': an HTTPS connection merely indicates that the connection is encrypted, not that the site is genuine.
If you suspect that a suspicious app is already on your phone, disconnect your phone from the internet, uninstall the app, change your password from another device, and contact your bank: this will ensure you’re back in the clear.
And remember that if even the current UK Prime Minister can be a scam target, perhaps you should remain vigilant too.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

Silvia Iacovcich is a tech journalist with over five years of experience in the field, including AI, cybersecurity, and fintech. She has written for various publications focusing on the evolving regulatory landscape of AI, digital behavior, web3, and blockchain, as well as social media privacy and security regulations.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.
