Original RecapCrime

Cybercriminals Target African Users with Fake Brand Impersonation Scams

Over 100 fraudulent websites impersonating major brands identified in Africa, raising security concerns.

NigerianNewsFeed NewsDesk
By NigerianNewsFeed NewsDesk Admin
@nigerianewsfeed · · 6 min read
Share:fXW
Cybercriminals Target African Users with Fake Brand Impersonation Scams
Photo: Legit

A new wave of cybercrime is sweeping across Africa, with criminals impersonating well-known brands to deceive users and steal sensitive banking information. Since August 2025, cybersecurity experts have identified over 100 fraudulent websites linked to this alarming malware campaign, which poses a significant threat to smartphone users in the region.

Major brands such as DStv, Takealot, South African Airways, and the South African Revenue Service (SARS) are reportedly being used by these cybercriminals to create convincing messages and websites that appear legitimate. The sophistication of this campaign has raised concerns among cybersecurity professionals, particularly in South Africa, where the Android operating system is widely used.

According to NordVPN, a cybersecurity firm, the attacks typically commence with social engineering tactics. Criminals send out convincing messages via SMS, WhatsApp, or social media, often featuring urgent offers or requests related to job opportunities, tax refunds, or identity verifications. Victims are then directed to fake websites that closely resemble the official sites of trusted organizations, where they are encouraged to download malicious Android applications.

Once these applications are installed, they can operate undetected in the background, even after the device is restarted. The malware may request extensive permissions, including access to SMS messages, contacts, and call logs, which can provide criminals with crucial information to compromise victims’ accounts. A particularly concerning aspect of this malware is its ability to intercept SMS messages containing one-time passwords (OTPs), undermining a key layer of banking security.

As the campaign continues to evolve, the professional appearance of the fraudulent websites suggests that artificial intelligence may be aiding criminals in creating these convincing replicas. The sites often utilize disposable domain extensions and are frequently updated, making them difficult to track.

Marijus Briedis, chief technology officer at NordVPN, advises Android users to exercise caution and avoid installing applications through unsolicited links. Users should be particularly wary of messages that create a sense of urgency, as these are often tactics employed by scammers.

For those who suspect they may have downloaded a malicious application, experts recommend disconnecting the affected device from the internet, removing the suspicious app, and changing important passwords from a secure device. It is also crucial to contact banks immediately to secure accounts against potential unauthorized access.

The rise in mobile banking attacks is alarming, with Kaspersky reporting a 1.5 times increase in such incidents globally in 2025. Bank-related phishing attacks accounted for 53.75% of all phishing detections recorded across Africa. This latest campaign underscores the growing risks that smartphone users face as cybercriminals increasingly exploit trusted brands to carry out their schemes.

In light of these developments, Nigerian banks, including Ecobank, have issued security advisories urging customers to be vigilant when downloading mobile applications. They warn that fraudsters are circulating fake advertisements and pop-up prompts across various platforms to lure users into installing malware-laden apps, highlighting the urgent need for increased awareness and caution among users.

Sources

NigerianNewsFeed NewsDesk
About the Author
NigerianNewsFeed NewsDesk Admin
Trusted, fast and relevant news across Nigeria and beyond.