Cybercriminals Target South Africans with Brand Imitation Scheme
Security researchers at NordVPN have uncovered a widespread phishing campaign targeting Android users in South Africa. The attackers are creating over 100 fraudulent websites that closely mimic legitimate organizations like DStv, Takealot, South African Airways, and even the tax authority SARS.
The campaign has been active since August 2025 and employs social engineering tactics to trick victims into downloading malicious apps. These fake sites often appear in SMS messages, WhatsApp chats, or on social media platforms with urgent calls to action.
Once downloaded, the app installs a remote access trojan that runs silently in the background, granting attackers extensive control over the device. This includes intercepting OTP codes used for transaction verification, effectively bypassing two-factor authentication measures.
Advanced Techniques Employed
The fraudulent websites exhibit an unusual level of sophistication, with researchers noting the likely use of generative AI in their design and localization efforts. Domain names are registered on disposable extensions like .cc, .lol, and .xyz, often hidden behind Cloudflare to evade detection.
This campaign arrives against a backdrop of rising mobile banking attacks across Africa. Kaspersky reports that bank-related phishing accounted for over 53% of all phishing detections on the continent in 2025 alone.
Staying Safe from Mobile Banking Threats
Experts recommend these precautions to protect yourself:
- Verify links before clicking: Be wary of messages urging immediate action or creating a sense of urgency
- Download apps only from official sources: Avoid installing apps from unknown websites or third-party app stores
- Enable two-factor authentication on all accounts and be suspicious of any requests to disable it
- Regularly review app permissions and uninstall anything you don’t recognize
- Keep your device software up to date with the latest security patches