Over 250 malicious apps found targeting Android users in worrying attack – here’s how to stay safe
- Researchers found 250+ fake dating apps targeting Android users
- The apps ask extensive permissions and end up stealing sensitive files
- Victims are later extorted under threat of releasing the files to friends and family
An “emotionally manipulative” extortion campaign has been spotted leveraging hundreds of mobile apps across mobile ecosystems.
Security researchers Zimperium zLabs claimed to have found more than 250 Android apps, all pretending to be dating and romance apps.
While they all look slick and well-designed, they all work as infostealers, grabbing contact information, photos, and other data from the devices. In some instances, the victims were lured into granting access through “emotionally charged interactions”, and exclusive “invitation codes”.
How to stay safe?
Zimperium calls the campaign SarangTrap, as it targets mostly people living in South Korea.
If the threat actors find any incriminating information on the compromised devices, they reach out to the victim and threaten to share it with their family, friends, and partners, unless a payment is made.
“This is more than just a malware outbreak, it’s a digital weaponization of trust and emotion,” said the zLabs research team. “Users seeking connection are being manipulated into granting access to some of their most personal data.”
To make matters worse, out of the 80 domains used in this campaign, many were allegedly indexed by popular search engines, making them appear legitimate to victims looking to do their due diligence.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
In its report, Zimperium advises mobile users against downloading apps from unfamiliar links, or unofficial app stores, hinting that none of the 250+ apps used in the campaign could be found on the Play Store, or App Store.
Apple and Google are quite diligent when it comes to their app repositories, and while malware finds its way in from time to time, it’s a lot harder to pick up malware on the official store, than on an unvetted, third-party one.
Users should also be careful of apps requiring unusual permissions or invitation code, regularly review the permissions they granted, and installed profiles they operate, and should install on-device mobile security solutions that can help detect and block malware.
You might also like
Researchers found 250+ fake dating apps targeting Android users The apps ask extensive permissions and end up stealing sensitive files Victims are later extorted under threat of releasing the files to friends and family An “emotionally manipulative” extortion campaign has been spotted leveraging hundreds of mobile apps across mobile ecosystems.…
Recent Posts
- Google Wallet ID passes will be available in select EU states this summer
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- Nomad Goods Promo Codes: Get 25% Off in June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023