Cybercriminals impersonate DStv, Takealot and South African Airways to steal bank details
Key Takeaways
- •More than 100 fraudulent domains have been linked to a campaign targeting South African Android users since August 2025.
- •The attackers impersonate well-known organisations such as DStv, Takealot, South African Airways and SARS to lure victims to fake websites.
- •Victims are tricked into installing an app that deploys a remote access trojan capable of intercepting banking one-time passcodes.
- •NordVPN said the malware can defeat two-factor authentication by allowing attackers to access and approve transactions in banking apps.
- •Users are advised not to install apps from message links and to disconnect, remove suspicious software, change passwords and contact their bank if they suspect infection.

Cybercriminals are impersonating DStv, Takealot, South African Airways, SARS, and other major organisations through more than 100 fraudulent websites to distribute malware that takes over banking apps on Android devices, according to a report by international cybersecurity company NordVPN.
The campaign has been active since August 2025 and targets South African Android users through social engineering. Victims receive messages via SMS, WhatsApp, or social media that contain links to fake websites designed to closely resemble legitimate organisations. SARS, the South African Revenue Service, is a frequent target of impersonation, and the tax authority regularly issues public warnings about fraudulent messages sent in its name.
After opening the site, victims are prompted to download an app that installs a remote access trojan on their device. Because the app is delivered through a browser link rather than an official app store, it bypasses the review applied to listings on Google Play; Android asks users for confirmation when installing software from unknown sources, and victims must approve that install for the trojan to take hold. Once installed, it runs in the background, survives phone restarts, and requests permissions that include access to SMS messages, contacts, call logs, screen capture, and audio recording.
Its most damaging capability is intercepting one-time passcodes, or OTPs, sent by banks for transaction verification.
“The malware effectively neutralises two-factor authentication,” NordVPN said. “Attackers can log into the victim’s banking app and approve the transaction themselves.”
NordVPN said the fraudulent websites show an unusual level of sophistication, with the likely use of generative AI in their design and localisation. The domains are registered on disposable extensions including .cc, .lol, .xyz, and .mom, while most are hidden behind Cloudflare, a content-delivery network whose proxy service masks the location of the server actually hosting a site, and replaced as soon as they are abandoned.
The campaign comes against a backdrop of increasing mobile banking attacks across Africa. According to Kaspersky, mobile banking attacks grew 1.5 times globally in 2025, while bank-related phishing accounted for 53.75% of all phishing detections on the African continent.
“Phishing and social engineering can lead people to fake banking pages, while infostealers and mobile banking trojans are designed to capture credentials or other sensitive information,” said Boris Larin, Chief Security Researcher at Kaspersky.
The scale of the operation targeting South Africa is significant. More than 100 domains have so far been linked to the campaign, and new ones appear as soon as old ones are abandoned. The deliberate use of high-trust brands familiar to South Africans is a key part of the scheme.
Android’s dominance in South Africa, where it accounts for more than 76% of the mobile operating system market, makes the country a particularly attractive target. With millions of South Africans managing their finances entirely through smartphones, the impact of a successful attack can extend far beyond a single compromised account.
Marijus Briedis, Chief Technology Officer at NordVPN, advised Android users never to install apps from links received through messages and to treat urgency in such communications as a warning sign. Any message that demands immediate action or pushes a user toward a deadline should be scrutinised rather than obeyed.
Users who suspect they have already installed a malicious app should immediately disconnect their phone from the internet, uninstall the suspicious app, change all passwords from a separate device, and contact their bank directly to secure their account. Suspected cybercrime can also be reported to the South African Police Service, which investigates offences under the Cybercrimes Act of 2020.
Read also: MultiChoice Nigeria to give DStv and GOtv subscribers free package upgrades throughout June