Monday, 24 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

'One install, and the phone is no longer yours' — NordVPN warns of fake Ryanair, Emirates, Qatar Airways apps used to spread malware

TechRadar ·
'One install, and the phone is no longer yours' — NordVPN warns of fake Ryanair, Emirates, Qatar Airways apps used to spread malware

NordVPN found a malware campaign impersonating 65 brands It tricks victims into clicking on messages requesting urgent action If you use an Android phone, it’s worth checking your apps Summer is still in full swing with many people out enjoying their holidays.

Unfortunately, cybercriminals never stop trying to steal money by tricking people into believing they are on trustworthy websites or using legitimate apps — especially when our attention is more likely to wander.

That’s what NordVPN , the pinnacle of the best VPNs , recently investigated, issuing an alert urging caution over a widespread and sophisticated malware campaign targeting Android users through highly convincing phishing schemes.

The malware is posing as over 65 well-known brands, including Ryanair, Emirates, and Qatar Airways, as well as tax authorities, registry offices, and social security systems that lure you into downloading their apps.

The dangerous trojan tracks your messages and logins, spies on you through your camera, records your voice, and bypasses two-factor authentication before ultimately draining your bank account.

The campaign has targeted users in Southeast Asia, Latin America, and Africa.

NordVPN – the best VPN overall NordVPN came out on top in our 2026 round of VPN tests.

We think it's the best VPN for most people.

We’re confident that virtually anyone can sign up for NordVPN and get what they need from it.

It’s easy to use, very secure, fast enough for gaming, and offers flawless streaming service unblocking.

Subscriptions start from $3.49 per month, and you can try it out risk-free with a 30-day money-back guarantee.

View Deal What the research found NordVPN spent the last 12 months investigating the malware campaign — including its infrastructure and impersonation targets — analysing malware clusters and mapping more than 100 domains linked to the campaign.

It discovered that the campaign tricks users into installing an app that grants full access to their Android phones or computers by impersonating highly trustworthy companies — brands people are accustomed to providing their personal data without questioning it.

Victims are lured by a variety of requests via SMS, WhatsApp, or social media that look totally innocuous, like a job opening at an airline, a cheap flight, or a tax refund.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›