Experts Sound Alarm Over Fake Android Streaming App Using VPN to Steal Banking Details
Cybersecurity experts have cautioned that using third-party streaming apps to watch sports and movies may expose users to financial loss and theft of personal data.
Cybersecurity experts have raised alarm over a malicious fake VPN app disguised as a streaming platform, which is being used to steal banking details from unsuspecting Android users.
The app lures users with free access to movies and live sports but secretly installs Klopatra—a newly discovered Android Remote Access Trojan (RAT). Once active, the malware grants cybercriminals full control of infected devices, allowing them to siphon funds and steal sensitive data.
According to a report by Digwatch, over 3,000 devices across Europe have already been compromised, with at least 1,000 victims suffering significant financial losses. Experts warn that the scam could soon spread to regions like Kenya, where third-party streaming apps are increasingly popular.
How it works
After installation, the malware tricks users into enabling Android’s Accessibility Services—features designed to help users with disabilities. With these permissions, attackers can read everything on the screen, access passwords, log into banking apps, and transfer money undetected.
Security researchers say the campaign likely originated in Turkey and is expanding globally. The malware operates silently in the background, bypassing traditional security measures by exploiting legitimate Android features.
How to stay safe
Experts advise Android users to:
-
Delete suspicious VPN or streaming apps not downloaded from verified sources like Google Play.
-
Regularly review which apps have Accessibility permissions and restrict them to trusted apps only.
-
Install reputable antivirus software and stay updated on emerging threats.
-
Immediately disconnect from the internet and change passwords if suspicious activity is detected.
With cybercriminals targeting entertainment-hungry users, experts stress that “free” streaming apps could come at the high cost of stolen identities and emptied bank accounts.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0