Cybercriminals impersonating DStv, SARS, other brands to steal bank accounts across Africa

By —

Cybercriminals are impersonating popular companies and government agencies across Africa in a campaign designed to take over smartphones and bank accounts. Over 100 fake websites linked to the malware campaign have been identified since August 2025.

How the scam works

Brands including DStv, Takealot and South African Airways, as well as the South African Revenue Service (SARS), are being used to make fraudulent messages and websites appear legitimate. According to cybersecurity company NordVPN, the campaign distributes Remote Access Trojans (RATs) and banking trojans, forms of malware that can give criminals control over infected devices and access to sensitive information.

The attacks are particularly concerning in South Africa, where Android dominates the mobile operating system market. NordVPN said the attacks typically begin with social engineering, where criminals send convincing messages through SMS, WhatsApp or social media. The messages may contain urgent offers or requests involving job opportunities, tax refunds, identity renewals or pension verification.

Victims are then directed to fake websites designed to closely resemble the official websites of trusted organisations. The sites encourage users to download an Android application. Once installed, the malicious software can operate quietly in the background, including after the smartphone is restarted.

Malware targets SMS passwords and bank security

The malware may request access to SMS messages, contacts, call logs, screen activity, audio and other device functions. These permissions can provide criminals with valuable information that can be used to compromise victims' accounts. One of the biggest threats is the malware's ability to intercept SMS messages containing one-time passwords (OTPs).

This can undermine an important layer of banking security, allowing criminals who have obtained banking credentials to potentially intercept authentication codes and gain access to accounts. NordVPN said the operation has been active since at least August 2025, with more than 100 domains linked to the campaign identified so far.

The cybersecurity firm also noted the professional appearance and localisation of the fraudulent websites, suggesting that artificial intelligence may have helped criminals create convincing replicas. The sites reportedly use disposable domain extensions and are frequently replaced when older domains are abandoned.

Experts: avoid unsolicited app downloads

NordVPN chief technology officer Marijus Briedis advised Android users never to install applications through links received in unsolicited messages. Users should also be suspicious of messages that create a sense of urgency or pressure them to act immediately.

Anyone who suspects they have installed a malicious application should disconnect the affected phone from the internet and remove the suspicious app. They should also change important passwords from a separate, trusted device and contact their bank immediately to secure their account.

Kaspersky security researcher Boris Larin previously warned that criminals are increasingly targeting credentials, devices and communications. Kaspersky research found that mobile banking attacks increased 1.5 times globally in 2025, while bank-related phishing accounted for 53.75% of phishing detections recorded across Africa.

What this means for Nigerian businesses and consumers

Ecobank has issued a security advisory urging customers to exercise caution when downloading mobile applications, warning that cybercriminals are deploying fraudulent apps to gain unauthorised access to personal banking accounts. The bank said fraudsters are circulating fake advertisements and pop-up prompts across social media platforms, websites and messaging applications to lure users into installing malware-loaded apps.

With mobile banking growing across Nigeria and Africa, the campaign is a reminder for consumers to verify URLs, avoid downloading apps from unsolicited links and never share one-time passwords. Banks and businesses should also invest in customer awareness as cybercriminals sharpen their use of trusted brand names.

Forex News

Consumer goods firms hold N587 billion cash as CBN rate cut threatens deposit income
ABOKI FOREX
Rivers, Abia Blackout: NUEE Action Trips Afam IV Transformer, TCN Confirms
ABOKI FOREX
FirstBank denies FirstMobile hack, says customers' funds are safe
ABOKI FOREX
Fuel marketers cut supply to airlines over unpaid debts as Abuja flights stall
ABOKI FOREX
Naira Gains in Official and Parallel Markets as FX Turnover Jumps 226% to $80.58m
ABOKI FOREX
Okin Biscuits Factory in Offa Nears Restart as Rehabilitation Hits 90%
ABOKI FOREX
Petrol Landing Cost Falls by N69.45 Per Litre as NNPC, MRS Cut Pump Prices
ABOKI FOREX
Tanzania Removes Nigeria From Referred Visa Category, Ends Two-Month Clearance Wait
ABOKI FOREX
FG moves to create Energy Zones for 24-hour power in Lagos, Abuja-Kaduna-Kano, Enugu-Port-Harcourt
ABOKI FOREX
OPay denies dropping phone numbers as account numbers, gives poster 30-minute ultimatum
ABOKI FOREX