Cybercriminals are impersonating DStv, Takealot, South African Airways, SARS, and other major organisations through over 100 fraudulent websites to distribute malware that takes over banking apps on Android devices. This is according to a report by international cybersecurity company NordVPN.
The campaign, which has been active since August 2025, targets South African Android users through a method known as social engineering. Victims receive messages via SMS, WhatsApp, or social media containing links to fake websites that closely mirror the appearance of legitimate organisations.

Once on the site, victims are prompted to download an app that installs a remote access trojan on their device. The trojan runs in the background, surviving phone restarts, and requests permissions including access to SMS messages, contacts, call logs, screen capture, and audio recording.
Its most damaging function is the interception of OTP codes sent by banks for transaction verification.
“The malware effectively neutralises two-factor authentication,” NordVPN said. “Attackers can log into the victim’s banking app and approve the transaction themselves.“
The fraudulent sites display an unusual level of sophistication, with NordVPN noting the likely use of generative AI in their design and localisation. Domain names are registered on disposable extensions including .cc, .lol, .xyz, and .mom, with most hiding behind Cloudflare and being replaced as soon as they are abandoned.
The cybercriminal threat landscape and how to stay safe
The campaign arrives against a backdrop of rising mobile banking attacks across Africa. Mobile banking attacks grew 1.5 times globally in 2025, while bank-related phishing accounted for 53.75% of all phishing detections on the African continent, according to Kaspersky.
“Phishing and social engineering can lead people to fake banking pages, while infostealers and mobile banking trojans are designed to capture credentials or other sensitive information,” said Boris Larin, Chief Security Researcher at Kaspersky.

The scale of the operation targeting South Africa is significant. Over 100 domains have been linked to the campaign so far, with new ones appearing as soon as old ones are abandoned. The deliberate targeting of high-trust brands that South Africans are accustomed to is not accidental.
Android’s dominance in South Africa, accounting for over 76% of the mobile operating system market, makes the country a particularly attractive target. With millions of South Africans managing their finances entirely through their smartphones, the consequences of a successful attack extend far beyond a single compromised account.
Marijus Briedis, Chief Technology Officer at NordVPN, advised Android users to never install apps from links received via messages and to treat urgency in such communications as a warning sign. Any message that demands immediate action or rushes a user toward a deadline deserves scrutiny, not compliance.
Users who suspect they have already installed a malicious app should immediately disconnect their phone from the internet, uninstall the suspicious app, change all passwords from a separate device, and contact their bank directly to secure their account.
Read also: MultiChoice Nigeria to give DStv and GOtv subscribers free package upgrades throughout June