Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

This dangerous new Android malware disguises itself as a VPN or IPTV app – so be on your guard

Tech Wavo by Tech Wavo
October 2, 2025
in Computers
0




  • Klopatra malware steals banking and crypto data, even when screen is off
  • Distributed via fake IPTV+VPN app, requests Accessibility permissions for full device control
  • Uses Virbox, anti-debugging, and encryption to evade detection and analysis

Cybersecurity researchers Cleafy have discovered a new, powerful Android trojan capable of stealing money from bank apps, stealing crypto from hot wallets, and even using the device while the screen is off.

Klopatra, an Android malware apparently built by a Turkish threat actor, does not resemble anything that’s already out there, meaning the tool was likely built from scratch. It was first spotted in March 2025, and since then has experienced 40 iterations, meaning the group is actively working on and developing the malware.

Klopatra is being distributed through standalone, malicious pages, rather than Google’s Play Store. It uses a dropper called Modpro IP TV + VPN, which pretends to be an IPTV and VPN app. Once the dropper is installed, it deploys Klopatra which, as usual for malicious apps, requests Accessibility Services permissions.


You may like

Thousands of victims

These permissions allow hackers to simulate taps, read screen content, steal credentials, and control apps silently – among other things.

Besides stealing people’s money, data, and fiddling around the phone, Klopatra also has a list of hardcoded Android antivirus names, which it then cross-references with the device and attempts to disable.

The malware also goes an extra mile to avoid being detected and analyzed.

It uses Virbox, a legitimate software protection and licensing platform, that defends apps against privacy, reverse engineering, and unauthorized use.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

In this case, Virbox was used to prevent cybersecurity researchers from reverse-engineering and analyzing the malware. Furthermore, it uses native libraries to bring its Java and Kotlin use to a minimum, and recently started using NP Manager string encryption.

The researchers said the malware comes with multiple anti-debugging mechanisms, runtime integrity checks, and the ability to detect when it’s running in an emulator, thus preventing researchers from dissecting it.

So far, at least 3,000 devices across Europe are infected, Cleafy said.

You might also like

Previous Post

Department of Energy cancels $7.5B of clean energy projects in mostly blue states

Next Post

Nespresso’s five-star beginner-friendly coffee maker is now under $100 at Amazon

Next Post
Nespresso’s five-star beginner-friendly coffee maker is now under $100 at Amazon

Nespresso's five-star beginner-friendly coffee maker is now under $100 at Amazon

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

NYT Strands hints and answers for Saturday, October 4 (game #580)

by Tech Wavo
October 4, 2025
0
NYT Strands hints and answers for Friday, October 3 (game #579)
Computers

Looking for a different day?A new NYT Strands puzzle appears at midnight each day for your time zone – which...

Read more

7 new movies and TV shows to watch on Netflix, Prime Video, HBO Max and more this weekend (October 3)

by Tech Wavo
October 4, 2025
0
7 new movies and TV shows to watch on Netflix, Prime Video, HBO Max and more this weekend (October 3)
Computers

After last week's TV show-heavy recommendations list, it's time to turn the spotlight on a whole host of new movies...

Read more

Apple’s future AR glasses could have a neat trick to improve your vision on the fly

by Tech Wavo
October 4, 2025
0
Apple’s future AR glasses could have a neat trick to improve your vision on the fly
Computers

Apple has patented a new lens system for its augmented reality glassesThe lenses could adapt based on your eyesight and...

Read more

Nanoleaf Smart Multicolor Floor Lamp review: a deceptively simple and affordable light with an app that could be more user friendly

by Tech Wavo
October 4, 2025
0
Nanoleaf Smart Multicolor Floor Lamp review: a deceptively simple and affordable light with an app that could be more user friendly
Computers

Why you can trust TechRadar We spend hours testing every product or service we review, so you can be sure...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock