{"id":20885,"date":"2025-10-09T18:42:18","date_gmt":"2025-10-09T18:42:18","guid":{"rendered":"http:\/\/localhost\/?p=20885"},"modified":"2025-10-09T18:42:18","modified_gmt":"2025-10-09T18:42:18","slug":"fake-vpn-and-streaming-app-drops-malware-that-drains-your-bank-account","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=20885","title":{"rendered":"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-09T22:44:05&#8243;,&#8221;description&#8221;:&#8221;Security researchers are warning Android users to delete a fake VPN and streaming app that can let criminals take over their phones and drain their bank accounts.\\n\\nThe app, Mobdro Pro IP TV + VPN, was discovered by researchers at Cleafy to be a malicious sideloaded app, not a legitimate VPN. Their analysis found it installs Klopatra, a new Android banking Trojan and remote-access tool with no links to known malware families.\\n\\nKlopatra targets banking customers and gives attackers full remote control of infected devices, allowing them to steal credentials and carry out fraudulent transactions.\\n\\nThe researchers found that:\\n\\n\\u003e \u201cKlopatra&#8217;s effectiveness lies in a carefully orchestrated infection chain, which begins with social engineering and culminates in the complete takeover of the victim&#8217;s device. Each stage is designed to overcome the defenses of the user and the Android operating system.\u201d\\n\\nThe lure works by pretending to be an IPTV app that offers free, high-quality TV channels. Because pirated streaming apps are so common, users often expect to install them from unofficial websites (sideloading), unintentionally bypassing the protections of the Google Play Store.\\n\\nKlopatra is an extreme example of a fake virtual private network (VPN) used to spread malware, but it\u2019s not the only reason to be cautious. Even genuine VPNs on Google Play can have hidden risks, from vague ownership to weak privacy protections.\\n\\n## Even genuine VPNs can be risky\\n\\nVPNs are often promoted as essential tools for privacy, circumventing geo-blocks, or bypassing age verification controls. For hundreds of millions of users, VPN connections are the solution to hide the user\u2019s IP address and location, and to encrypt web traffic so it&#8217;s useless when intercepted.\\n\\nBut picking a VPN you can trust is not always easy. Even if you get one from the official Play Store. \\n\\nA recent study, the VPN Transparency Report 2025 by the Open Technology Fund, revealed alarming shortcomings among some of the world&#8217;s most-downloaded VPN apps. The researchers examined the ownership, operation, and development of 32 commercial VPNs, collectively used by more than a billion people.\\n\\nAmong the apps flagged as \u201cconcerning\u201d are very popular solutions like Turbo VPN, VPN Proxy Master, XY VPN, and 3X VPN \u2013 Smooth Browsing, each of which has been downloaded at least 100 million times from the Google Play Store.\\n\\nSome of these solutions even provide a false sense of privacy by using technologies that weren\u2019t designed for privacy at all, the study claims. They found that several:\\n\\n\\u003e \\&#8221;providers use the Shadowsocks tunneling protocol [which is not designed for confidentiality] to build the VPN tunnel, and claim their users&#8217; connections are secure.\\&#8221;\\n\\nThe report emphasizes how important it is to gather information before installing a VPN: it\u2019s worth learning who runs it, how it\u2019s built, and what it does with your data. This is key for users to make informed decisions.\\n\\n## Practical tips on how to protect yourself\\n\\n  * **Stick to trusted sources.  **Download apps\u2014especially VPNs and streaming services\u2014only from Google Play, Apple\u2019s App Store, or the official provider. Never install something just because a link in a forum or message promises a shortcut.\\n  * **Check an app &#8216;s permissions. **If an app asks for control over your device, your settings, Accessibility Services, or wants to install other apps, stop and ask yourself why. Does it really need those permissions to do what you expect it to do?\\n  * ****Use layered, up-to-date protection.** **Install** **real-time anti-malware protection on your Android that scans for new downloads and suspicious activity. Keep both your security software and your device system updated\u2014patches fix vulnerabilities that attackers can exploit.\\n  * **Stay informed.  **Follow trustworthy cybersecurity news and share important warnings with friends and family.\\n\\n\\n\\n### **If you think you\u2019ve been affected:**\\n\\nDelete any suspicious VPN or IPTV apps, run a trusted security scan, and reset your banking credentials if you suspect your device has ever been compromised. For your peace of mind and your wallet\u2019s safety, choose your VPN wisely.\\n\\n* * *\\n\\n**We don &#8216;t just report on privacy\u2014we offer you the option to use it.**\\n\\nPrivacy risks should never spread beyond a headline. Keep your online privacy yours by using Malwarebytes Privacy VPN.&#8221;,&#8221;published&#8221;:&#8221;2025-10-09T19:05:39&#8243;,&#8221;modified&#8221;:&#8221;2025-10-09T19:05:39&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Fake VPN and streaming app drops malware that drains your bank account&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2025\/10\/fake-vpn-and-streaming-app-drops-malware-that-drains-your-bank-account&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-09T22:44:05&#8243;,&#8221;description&#8221;:&#8221;Security researchers are warning Android users to delete a fake VPN and streaming app that can let criminals take over their phones and drain their&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-20885","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=20885\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-10-09T22:44:05&#8243;,&#8221;description&#8221;:&#8221;Security researchers are warning Android users to delete a fake VPN and streaming app that can let criminals take over their phones and drain their...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=20885\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-09T18:42:18+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20885#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20885\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1\",\"datePublished\":\"2025-10-09T18:42:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20885\"},\"wordCount\":859,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20885#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20885\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20885\",\"name\":\"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-10-09T18:42:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20885#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20885\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20885#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=20885","og_locale":"en_US","og_type":"article","og_title":"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-10-09T22:44:05&#8243;,&#8221;description&#8221;:&#8221;Security researchers are warning Android users to delete a fake VPN and streaming app that can let criminals take over their phones and drain their...","og_url":"https:\/\/zero.redgem.net\/?p=20885","og_site_name":"zero redgem","article_published_time":"2025-10-09T18:42:18+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=20885#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=20885"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1","datePublished":"2025-10-09T18:42:18+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=20885"},"wordCount":859,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=20885#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=20885","url":"https:\/\/zero.redgem.net\/?p=20885","name":"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-10-09T18:42:18+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=20885#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=20885"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=20885#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Fake VPN and streaming app drops malware that drains your bank account_MALWAREBYTES:AECCF9E8FE462E07900EAD956B8995C1"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20885"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20885\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}