Summary is AI-generated, newsdesk-reviewed
  • Zimperium's SarangTrap targets mobile users via fake dating, social networking apps.
  • Over 250 malicious Android apps, 80 phishing domains steal sensitive data.
  • Caution urged: avoid unusual permissions, unfamiliar app links, regularly review permissions.

Zimperium, the world pioneer in mobile security, announced that its zLabs threat research team has uncovered a highly coordinated and emotionally manipulative malware campaign that is targeting mobile users through fake dating and social networking apps.

The campaign, identified as SarangTrap, has already leveraged over 250 malicious Android apps and more than 80 phishing domains, all designed to steal sensitive data while masquerading as trusted platforms.

Legitimate dating services

These apps, once installed, request access to contacts, images, and other sensitive data, all while presenting a slick, believable interface that mimics legitimate dating services.

Victims have reported being lured in with emotionally charged interactions and exclusive “invitation codes,” only to later face extortion threats after their private information was silently exfiltrated.

Malicious configuration profiles on iOS

The campaign is active across both Android and iOS platforms, using deceptive installation methods

This is more than just a malware outbreak, it’s a digital weaponisation of trust and emotion,” said the zLabs research team. “Users seeking connection are being manipulated into granting access to some of their most personal data.”

The campaign is active across both Android and iOS platforms, using deceptive installation methods such as malicious configuration profiles on iOS to gain access to contacts, photos, and device identifiers. Many of the phishing domains were even indexed by popular search engines, making them appear legitimate to unsuspecting users searching for dating or social apps.

Zimperium strongly urges mobile users

  • Be cautious of apps requiring unusual permissions or invitation codes
  • Avoid downloading apps from unfamiliar links or unofficial app stores
  • Regularly review device permissions and installed profiles
  • Install on‑device mobile security solution to help detect and block malicious apps

Stay ahead of the trends on securing physical access control systems through layered cybersecurity practices.

In case you missed it

What are emerging applications for physical security in transportation?
What are emerging applications for physical security in transportation?

Transportation systems need robust physical security to protect human life, to ensure economic stability, and to maintain national security. Because transportation involves moving...

Gallagher & Fortified enhance perimeter security solutions
Gallagher & Fortified enhance perimeter security solutions

Global security manufacturer - Gallagher Security is proud to announce a strategic partnership with Fortified Security, a pioneering perimeter systems integrator with over 30 years...

Genetec: Data sovereignty in physical security
Genetec: Data sovereignty in physical security

Genetec Inc., the global pioneer in enterprise physical security software, highlights why data sovereignty has become a central concern for physical security leaders as more survei...