Press ESC to close

How to Spot a Fake App Designed to Steal Your Money: Watch Out for These Scam Apps

Today, a mobile phone is also a wallet, a gateway to your bank, a password vault, and the place where you receive authorization codes by SMS. That is precisely why fake and malicious apps are so attractive to scammers. Some impersonate banks or well-known services, others offer loans or investments, while still others pose as completely harmless apps.

A fake app can often be identified by a combination of warning signs: a suspicious installation method, excessive permissions, an unknown developer, pressure on the user, and requests for access to SMS messages, the screen, or banking details. The biggest red flag is when someone calls or messages you and tries to persuade you to install a specific app.

A scam app may not look suspicious at first glance

The idea that malicious apps can be recognized by amateurish logos, grammatical errors, and zero downloads is long outdated. Modern scam apps can have professional designs and thousands of reviews, and some have even made it onto the official Google Play store in the past.

Google said that during 2025 it prevented more than 1.75 million apps that violated Google Play policies from being published and blocked more than 80,000 problematic developer accounts. Play Protect also identified millions of new malicious apps originating outside Google Play. An app's presence in the store therefore significantly reduces the risk, but it is not an absolute guarantee of safety.

Scammers also frequently change not only the technical setup, but also the name, icon, and story used to persuade the victim. An app promoted today as an investment tool may be distributed under a completely different name a few weeks later.

The biggest warning sign: someone tells you what to install

One of the most reliable warning signs is not the app itself, but how you came across it. A bank, the police, the National Bank of Slovakia, or a reputable investment adviser will not call and persuade you to install an unknown app from a link sent by SMS, WhatsApp, or email while you are still on the phone.

The scam often begins with a phone call. The caller claims that a suspicious transaction is taking place on your account, that you have forgotten investments somewhere, or that your money needs to be “secured.” They then send you a link to an app and explain exactly where to tap.

If someone guides you step by step through installing an app, entering banking details, or changing your phone's security settings, end the call.

The app requests permissions it does not need

Permissions are among the most important things to check when installing an app. A request for access to contacts or location does not necessarily indicate fraud. What matters is whether the app genuinely needs that data for its stated purpose.

Accessibility access is particularly suspicious

On Android, Accessibility is a highly sensitive permission. It legitimately serves purposes such as helping people with disabilities, but it can also allow an app to monitor screen content and perform certain actions on the user's behalf.

In 2025, SK-CERT described malware targeting Czech and Slovak users that abused this very permission. Once granted, it could automatically approve additional permissions, record the screen, and even control supported banking apps.

If a simple game, video player, loan app, or supposed investment app requests Accessibility access, that is a reason to stop the installation immediately.

Beware of permission to install other apps

Another dangerous sign is a request to allow the app to install other apps from unknown sources. This can turn an initially simple app into a gateway for additional malware.

In some attacks, the first app contains only a minimal amount of malicious code, while the actual malware is downloaded to the phone later. As a result, users may not see everything the app will ultimately be capable of doing during the initial installation.

SMS messages, notifications, and the screen

Access to SMS messages and notifications is highly sensitive because they may contain authorization codes from your bank. The ability to record or remotely control the screen is also dangerous.

If an app requests several of these permissions at once despite having no legitimate reason to use them for its normal operation, that is a major warning sign.

Beware of the “TikTok 18+ – Opravdu krátká videa” app

One very specific example directly affected Slovakia and the Czech Republic. On September 10, 2025, SK-CERT warned about malicious Android apps that enabled sophisticated theft of money and cryptocurrencies.

In one recorded campaign, users were lured by an advertisement for an app called:

TikTok 18+ – Opravdu krátká videa

It was not the official TikTok app.

After the first app was installed, the attack continued by downloading additional malware components. One requested Accessibility access and could then automatically obtain further permissions.

According to SK-CERT, the malware could record the screen, read or modify copied text, control WhatsApp and Facebook, send SMS messages, and interact with supported cryptocurrency wallets. It could also control a supported online banking app and carry out the steps needed to make a bank transfer.

One more point is important: the name “TikTok 18+ – Opravdu krátká videa” was not the essence of the attack. The attackers could change the name, advertisement, and story used to lure victims. Memorizing a single app name is therefore not enough.

SpyLoan: malicious loan apps had millions of downloads

Another excellent example of why a professional-looking app should not automatically be trusted is the group of apps dubbed SpyLoan by cybersecurity company ESET.

The apps posed as quick-loan services. In 2023, ESET identified 18 such apps and reported them to Google. Seventeen were subsequently removed from Google Play. Before their removal, they had amassed more than 12 million downloads in total.

These were therefore not apps used by only a few dozen people who found them on a dubious website.

The apps collected sensitive information from devices. ESET described access to contacts, SMS messages, call logs, calendars, device information, and files, among other data. The information obtained could then be used to pressure and blackmail users in connection with the loans.

Names of apps linked to the SpyLoan case

Apps identified in the research included:

  • AA Kredit
  • Amor Cash: Préstamos Sin Buró
  • Oro Préstamo – Efectivo rápido
  • Cashwow
  • CrediBus Préstamos de crédito
  • PréstamosCrédito – GuayabaCash
  • Préstamos De Crédito – YumiCash
  • Go Crédito – de confianza
  • Instantáneo Préstamo
  • Cartera grande
  • Rápido Crédito
  • Finupp Lending
  • 4S Cash
  • TrueNaira – Online Loan
  • EasyCash

With older security incidents, it is also important to consider the time frame. This list identifies apps and packages found during a specific investigation. It does not mean that apps with the same names are still available today, or that a new app using a similar name is automatically the same app.

That is why security analysts often examine an app's unique package name, digital signature, and other technical data, rather than relying only on the name shown to users.

A fake app can imitate a genuine financial service

Back in 2017, ESET also documented two apps posing as the legitimate cryptocurrency service Poloniex. They appeared on Google Play under the names:

  • POLONIEX
  • POLONIEX EXCHANGE

However, the apps did not come from the legitimate service. They displayed a fake login screen and attempted to steal users' login credentials.

This type of attack is particularly dangerous because users do not have to be searching for an unknown service. On the contrary, they may enter the name of a company they know into the app store and find an imitation among the results.

How to verify that a banking or financial app is genuine

The safest approach is not to rely solely on app-store search results. Open the official website of the bank, exchange, or financial company and check whether it provides a link to its official mobile app.

Check the developer's name

An app's name is very easy to imitate, as are its icon and store listing images. The name of the company or developer that published the app is more important.

If you are looking for a major bank's app and the listed developer is an unknown company with no obvious connection to the bank, do not enter any information into it.

Check its history and negative reviews

The star rating alone is not enough. Fake positive reviews can be created or purchased. In its warning about fraudulent loan apps, ESET noted that negative reviews may reveal users' real experiences.

Suspicious signs can include large numbers of almost identical five-star reviews, unnatural wording, or a sudden surge of reviews within a short period.

Even a million downloads does not automatically mean an app is safe. The SpyLoan case is clear proof of that.

Does an investment app show huge profits? They may be nothing more than numbers on a screen

Investment scams present another problem: the app or online platform may not be conducting any actual trades.

The National Bank of Slovakia warns about scams in which victims deposit money and then watch the value of their supposed investment rise rapidly on the screen. The balance shown in the app may simply be a fictitious number created by the scammer.

The problem arises when the user tries to withdraw the money. They are told they must pay another fee, tax, AML check fee, or source-of-funds verification charge. After they pay, another obstacle appears and the scammer demands more money.

If an app shows a large profit but requires you to send more money before it can be paid out, do not send anything.

A familiar app name does not necessarily mean the app itself is fraudulent

It is important to distinguish between two completely different situations. A scammer may create a malicious app, but they can also misuse a legitimate app for remote access, communication, or monitoring cryptocurrency prices.

In August 2025, the NBS warned about scammers misusing the NBS Shares brand. According to the bank, victims were instructed to install remote-access apps or other tools, for example.

The warning mentioned CoinMarketCap, for example. However, that does not mean CoinMarketCap is a scam app. A fraudster can use a legitimate service as a prop and show the victim data intended to support a fabricated story.

Similarly, a legitimate app for remotely managing a computer or phone may be safe under normal use, but extremely dangerous if you voluntarily use it to hand control over to a stranger.

Never disable security features on the instructions of someone on the phone

If an app or someone on the phone tells you to disable Google Play Protect, allow installation from unknown sources, or ignore a security warning on your phone, that is one of the strongest warning signs.

In newer versions of Android, Google is introducing protections specifically designed to counter this type of social engineering. Certain high-risk settings are restricted during calls from unknown numbers because scammers often guide victims through the installation of malicious apps in real time.

No reputable bank or technical support service needs you to weaken your phone's security.

Beware of fake system warnings

Another trick involves messages such as:

“Your phone is infected with 7 viruses.”

“Your banking details have been compromised.”

“You must install a security app immediately.”

If a similar message appears as an advertisement in a web browser or inside a game, it is not a system diagnostic from your phone. Its purpose may be to direct you to a page offering another app, a subscription, or a malicious file.

A genuine Android or iOS security warning does not appear as an advertising banner on a website.

How to spot a fake app before installing it

Before downloading a financial, investment, or banking app, it is worth carrying out a few simple checks:

  1. Verify the app through the company's official website.
  2. Check the developer's exact name.
  3. Check the number of downloads, but do not treat it as proof of safety.
  4. Pay particular attention to the most recent negative reviews.
  5. Check what data the app collects.
  6. Consider whether the requested permissions make sense for the app's purpose.
  7. Do not install an APK file sent by SMS, Messenger, WhatsApp, or email.
  8. Do not grant Accessibility access without a clear and trustworthy reason.
  9. Do not allow an unknown app to install other apps.
  10. Never disable security features on the instructions of a stranger.

If an app was recommended by someone who unexpectedly called you moments earlier with an investment offer or a claim about a problem with your bank account, the safest option is not to install it at all.

What to do if you have already installed a scam app

The appropriate response depends on what permissions the app obtained. If it was an ordinary app without sensitive permissions, removing it and checking the device may be sufficient. However, if it had access to SMS messages, notifications, Accessibility, the screen, or remote-control features, the situation should be treated as more serious.

Contact your bank immediately

If the app may have been able to see your online banking, payment card, SMS messages, or authorization details, contact your bank using its official phone number. Do not call the number used by the supposed bank employee who contacted you earlier.

Check your transactions, payment cards, and any changes to account limits.

Change passwords from a secure device

If the phone may still be controlled by the attacker or recording the screen, do not use it to change your most important passwords. Sign in from another trusted device.

Start with your email account, because email is often used to reset passwords for many other services. Then change the passwords for your bank and other important accounts.

A factory reset may be necessary after a serious compromise

For the specific campaign distributed as “TikTok 18+ – Opravdu krátká videa,” SK-CERT recommended restoring the phone to factory settings. Simply removing the original app might not have been enough because it had already installed additional malware components.

If an app gained extensive control over the phone, a factory reset may be safer than attempting to find and remove all its components manually.

How to protect yourself on Android

Google Play Protect should remain enabled. It checks apps from Google Play as well as potentially harmful apps from other sources, and it can warn the user, disable an app, or remove it.

Keep Android and your apps updated as well. Newer security mechanisms can restrict some of the permissions or installation methods that scammers exploited on older devices.

However, the user remains the most important line of defense. Even technical safeguards may not help if someone follows a scammer's instructions to gradually disable every protection, allow unknown sources, and voluntarily give a malicious app access to the screen.

How to check apps on an iPhone

iPhone users should also check who published an app and what permissions it requests. Apple provides the App Privacy Report feature, which lets users see how often individual apps access data such as location, camera, or microphone, and which internet domains they communicate with.

If an app uses sensitive data in a way that does not match its purpose, you can revoke the permission in the privacy settings.

Even on an iPhone, users should not blindly trust every app simply because it looks professional.

Five situations in which you should not install an app

Close the app immediately if even one of the following applies:

  • an unknown person sent it to you during a phone call,
  • it requires you to disable your phone's security protections,
  • it requests Accessibility access without a reasonable justification,
  • it promises virtually guaranteed returns and pressures you to deposit money immediately,
  • its developer or origin cannot be linked to the company the app claims to represent.

If several of these warning signs appear at once, the risk increases sharply.

The most dangerous app is the one we trust

The most successful scam apps often do not look like viruses. They look like banking apps, investment platforms, loan services, security tools, or entertainment apps. That is their greatest advantage.

Memorizing a list of dozens of names is therefore not enough. Attackers can change the name, logo, and advertisement almost instantly. It is far more important to recognize how scammers try to get an app onto your phone and what permissions it subsequently requests.

If someone pressures you to make a quick decision, wants to see your screen, asks for access to your phone, or claims that you must install something immediately to protect your money, the safest response is to end the conversation and contact the bank or company independently using its official contact details.

Sources

  1. SK-CERT – Malicious mobile app also targeting Slovak customers, September 10, 2025. SK-CERT – Malicious mobile app also targeting Slovak customers
  2. National Bank of Slovakia – Beware of scams!, updated August 6, 2026. NBS – Beware of scams!
  3. National Bank of Slovakia – Warning about a new type of scam misusing the NBS brand, August 26, 2025. NBS – Warning about a new type of scam misusing the NBS brand
  4. Google – How Google Play and Android app ecosystems stayed safe in 2025, February 19, 2026. Google – How Google Play and Android app ecosystems stayed safe in 2025
  5. ESET Research – Beware of predatory fin(tech): Loan sharks use Android apps to reach new depths, December 5, 2023. ESET Research – Beware of predatory fin(tech)
  6. ESET Research – Fake cryptocurrency trading apps on Google Play, October 23, 2017. ESET Research – Fake cryptocurrency trading apps on Google Play
  7. FBI – Cryptocurrency Investment Fraud. FBI – Cryptocurrency Investment Fraud
  8. Apple Support – About App Privacy Report, updated December 19, 2025. Apple Support – About App Privacy Report

Jana

I like turning curiosity into words, and writing articles is my way of capturing ideas before they slip away — and sharing them with anyone who feels like reading.