NordVPN says criminals are running more than 100 fake websites impersonating Takealot, DStv, South African Airways, SARS and other trusted names across Africa, to trick people into installing Android malware.
Victims receive an SMS, WhatsApp or social media message carrying a plausible hook: a job at an airline, a pending tax refund, a pension verification request. The link opens a convincing copy of the real site, which then prompts an app install.
Interesting insights on SA banking trojan
This lands harder here than in most markets because Android holds more than 76% of the South African mobile operating system market, according to StatCounter. Once installed, the trojan runs quietly in the background, survives a reboot, and requests permissions no airline or government app would need: reading SMS messages, contacts and call logs, capturing the screen, recording audio and activating the camera.
The critical capability is SMS interception, which reads the one-time PIN your bank sends and lets an attacker sign in and approve transactions. SMS-based two-factor authentication is not weakened by this; it is neutralised.
The campaign has been running since at least August 2025. Every page is professionally localised, which NordVPN attributes to generative AI, and the domains sit on disposable extensions like .cc, .lol, .xyz and .mom, with Cloudflare used as a shield.
What others are saying about SA banking trojan
MyBroadband reported the research and NordVPN chief technology officer Marijus Briedis's advice never to install an app from a link received in a message, and to treat urgency itself as a warning sign. MyBroadband separately reported Kaspersky's finding that mobile banking attacks grew 1.5 times globally in 2025, with bank-related phishing making up 53.75% of all phishing detections across Africa. StatCounter tracks the Android share that makes the country such a productive target.
Your brand is the bait, and SMS OTP is finished
Two things here belong on a founder's list this week. Takealot, DStv and SAA did nothing wrong. Their brands are the attack surface, and there is no patch for that, so if your customers trust you enough to click, you need a published channel policy, an easy way for someone to verify a message is really from you, and somebody watching for lookalike domains.
The more urgent point is authentication. If your product still verifies users with an SMS one-time PIN, that factor is gone on any compromised Android handset.
App-based authenticators and passkeys are the answer, and that migration takes months. Start it before your fraud numbers decide for you.
You might also like our piece on the Lego South Africa data breach that handed criminals a phishing list, the stolen browser cookies circulating locally, and what FSCA record fines say about deepfakes beating verification.
Get more SA tech and business news and subscribe to The Open Letter.


