Site navigation

Fake Dating Apps Uncovered in Global Malware Campaign

Graham Turner

,

Fake dating apps
Over 250 malicious apps and 80 phishing domains have been identified, with the campaign still active and evolving.

A large-scale malware operation using fake dating and social networking apps to steal sensitive personal data has been uncovered by cybersecurity researchers.

The campaign, dubbed “SarangTrap,” has targeted both Android and iOS devices, leveraging more than 250 malicious apps and over 80 phishing domains to trick users into sharing private information.

According to a report released by mobile security firm Zimperium on Wednesday, the scheme combines social engineering with advanced spyware techniques.

Victims are lured through fake profiles, exclusive “invitation codes,” and convincing app interfaces that mimic legitimate dating platforms. Once installed, the apps request access to contacts, photos, SMS content, and device identifiers, then secretly transmit this data to servers controlled by the attackers.

Zimperium’s zLabs research team found that newer Android samples have been modified to remove visible SMS permissions while still retaining the capability to exfiltrate messages. This appears to be a strategy to evade detection by security scans.

On iOS, the attackers use malicious mobile configuration profiles rather than traditional app installations. These profiles allow access to contacts, images, and device information without raising immediate suspicion.

The threat actors behind SarangTrap have registered 88 unique domains, more than 70 of which are currently active in distributing malware. At least 25 of these domains have been indexed by search engines, ranking for popular terms related to dating, file sharing, and social networking, making them appear credible to potential victims.

The campaign relies not only on technical sophistication but also emotional manipulation. Zimperium highlighted an incident where a man grieving a breakup was targeted via a fake dating profile. After installing one of the malicious apps and entering a code, his private data was stolen and later used for blackmail, with threats to expose personal videos to his family.


Recommended reading


“The SarangTrap campaign is more than just a malware outbreak—it’s a weaponisation of trust and emotion,” the zLabs team said in a statement. “Users seeking connection are being manipulated into granting access to some of their most personal data.”

Zimperium warns that the operation remains active and is continuing to evolve. Users are advised to avoid apps that request invitation codes or unusual permissions, steer clear of unofficial app stores, review installed configuration profiles, and use mobile security tools to detect malicious activity.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data