Thank you for subscribing!

If you've received a WhatsApp message from Ryanair, you'll want to hit the delete button immediately. Hackers have launched a worldwide malware campaign, sending WhatsApp messages claiming to be from over 65 well-known brands, including airlines like Ryanair and Emirates, government agencies, and more.

It's all designed to trick you into clicking on a link and downloading what looks like a legitimate app, but is actually a banking trojan that hands criminals full remote control of the victim's phone.

Once installed, attackers can read text messages, watch the screen live, and even switch on the camera and microphone — all to drain bank accounts.

Discovered by the team at NordVPN Threat Intelligence, criminals reach out through WhatsApp, SMS, or social media posts with messages that sound completely plausible — things like a job offer at an airline, a tax refund waiting to be claimed, a reminder to renew an ID, a pension check, or a bargain flight deal.

Marijus Briedis, chief technology officer at NordVPN, said: "What makes this campaign dangerous is how ordinary the bait is. A tax refund or a flight deal does not feel like a threat; it feels like good news. One install, and the phone is no longer yours. The attacker sees your screen, reads your SMS codes, and empties your accounts from the inside."

If you tap the link, you're then taken to a website disguised to look real. It's even translated into the local language, so someone in Manila, Mexico City, Jakarta, or Sydney sees a page that feels entirely familiar.

The site then nudges you to install an Android app — and that's where the trouble starts.

Qatar Airways is among the airlines being impersonated, alongside government bodies that you might not second-guess with your personal details, like civil registries, social security systems, and healthcare providers.

Once the app is on your phone, it runs silently in the background — and it doesn't go away when you restart the device. It demands permissions no genuine airline or government app would ever ask for — access to your texts, contacts, call logs, screen, microphone, and camera.

The really dangerous part is its ability to intercept SMS messages. Since most banks still send one-time security codes by text, the malware essentially makes two-factor authentication useless. Criminals can log straight into a victim's banking app and approve transactions themselves.

NordVPN's analysts have linked more than 100 web domains to the campaign, which has been running since at least August of last year across Asia, Australia, the Middle East, Latin America, and Europe. The attackers constantly swap out their infrastructure, registering throwaway domains with extensions like .cc, .lol, .xyz, and .mom.

So what should you do to protect yourself? Mr Briedis recommends never installing an app from a link someone sends you in a message. Genuine airlines, banks, and government services put their apps on Google Play — they don't send download links over SMS or WhatsApp.

If a message is pushing you to act immediately — claiming a prize is about to expire, a refund deadline is looming, or your account is locked — treat that urgency as a red flag, not a reason to rush.

Have a look at the web address, too. Real organisations don't run their sites on domains ending in .cc, .lol, .xyz, .mom, or .pw. And don't assume a padlock icon means a site is safe — it just means the connection is encrypted. Encryption keeps private information safe so that only people with the right digital key can read it, such as the person who sent it and the intended recipient.

If you've already installed something dodgy, it's best practice to disconnect your phone's internet connection straight away, delete the app, change your passwords from a different device, and call your bank to explain what happened as a precaution.