“We are going to activate your 5G” or “you have an approved card”: the scams that take control of your cell phone and bank accounts

“We are going to activate your 5G” or “you have an approved card”: the scams that take control of your cell phone and bank accounts
  • Almost half of SMEs suffered a cyberattack in the last year: these are the threats that worry the most
  • Red Cross creates “digital emblem” to extend humanitarian protection to cyberspace

You receive a call from the bank. The person on the other end of the line knows your full name and offers you a new credit card. In another case, a supposed phone operator promises to activate 5G on your cell phone to improve the signal. Although the stories are different, both share the same pattern: they are part of a trend that worries cybersecurity specialists. Digital scams have become much more sophisticated and convincing.

Read more Paolo Guerrero and Christian Cueva star in an emotional reunion after the Alianza Lima vs. Sport Boys match

The cases were alerted by a TikTok user specialized in technology content. In the first, he narrates how he received a call from a supposed agent of Banco de Crédito (BCP), who offered him an “Infinity Iridium” card with a credit line of S/30,000 and 20,000 Latam Pass miles as a welcome gift.

WATCH: The context bomb, cybersecurity’s secret weapon to stop AI agent attacks

Apparently, the scammer already had basic data of the victim, such as their name and phone number. The goal was clear: to convince them to install malware on their cell phone. To achieve this, he used the delivery of the card as a pretext. After accepting the offer, the supposed advisor asked if he had WhatsApp so that the bank’s Digital Area could contact him and perform a supposed “service update.” Minutes later, the victim received a message with a file called “BCP benefits 2026”. In the WhatsApp preview, it was seen that it was an APK file, the format used to install applications on Android. If the user opened it, they fell into the trap.

Criminals seek to access banking applications to make transfers or steal victims' financial information.
Criminals seek to access banking applications to make transfers or steal victims’ financial information.
/ Unsplash

In the second case, the attacker impersonated a Claro operator. He initiated contact claiming that the “satellite signal had dropped,” which supposedly explained a decrease in service speed. To solve the problem, he offered three benefits: migrate the line to 5G, grant a discount on the monthly bill, and perform a system update via a link sent through WhatsApp.

@antonio.alban Today I share an attempted scam I received from a supposed call from Banco de Crédito / BCP in Peru. They sent me an APK file to install on my phone, intending to compromise my security and gain access to my information. In this video, I show you how these types of frauds operate, what signs you should identify, and why you should never install APK files sent by strangers or supposed bank advisors. If you receive a similar call, end the communication, do not open links or install anything, and always verify with the bank’s official channels. Share this video so more people stay alert and don’t fall for these types of scams @Banco de Crédito BCP #EstafaPeru #BCP #DigitalSecurity #APKWarning #BankFraud ♬ original sound – Antonio Alban
@antonio.alban Again they want to scam me, new update, now with the story of paying 50% less on your Claro bill, what do you think @canalclaroperu ?? #cybersecurity #scam #claro #whatsapp #claroperu ♬ original sound – Antonio Alban

Two scams, the same strategy

At first glance, both frauds seem different: one offers a credit card and the other promises to improve mobile connection. However, they share the same goal: to convince the victim to install a malicious file on their phone to take control of the device and access financial information.

What do criminals gain when the victim installs the APK file? They incorporate a banking trojan, a type of malware designed to remain hidden inside the device and capture sensitive information.

According to our research, modern banking trojans are designed to integrate into the device’s normal operation and remain hidden as long as possible. During installation, they request permissions that seem necessary for the app’s operation, but actually allow them to interact with critical operating system functions,” says Julio Seminario, cybersecurity specialist at Intecnia Corp, Bitdefender’s Country Partner in Peru.

Fake 5G activations have become one of the new pretexts used by cybercriminals to distribute malware.
Fake 5G activations have become one of the new pretexts used by cybercriminals to distribute malware.
/ Unsplash

The specialist explains that once those permissions are obtained, the malware can detect when the user opens banking apps or digital wallets and display fake interfaces practically identical to the originals to capture usernames, passwords, and other authentication data. Since the screen looks identical to the legitimate one, many victims do not realize they are handing their information directly to the attackers.

WATCH: Peru surpassed more than 350,000 digital threats so far in 2026, warns ESET

Additionally, these malicious programs can access SMS messages and notifications to intercept one-time authentication codes (OTP), “a security measure widely used by financial institutions.” Some variants even incorporate remote access capabilities, allowing cybercriminals to control certain device functions and complete fraudulent operations while the user continues to use it seemingly normally.

This combination of credential theft, security code interception, and remote control makes banking trojans one of the most dangerous threats for mobile banking users,” Seminario states.

Criminals no longer improvise

Just as security tools evolve, so do cybercriminals’ strategies. Gone are the days of mass emails full of spelling errors or unbelievable promises. Today, criminals build personalized scenarios to gain their victims’ trust.

Today cybercrime operates like an industry. There are specialized groups that only steal information and then sell it to other criminals who use it to execute much more credible scams,” says Jorge Zeballos, cybersecurity specialist at ESET Peru.

According to the expert, the fact that an attacker knows the name, surnames, and even other personal data shows that “we are no longer facing massive and generic campaigns, but highly personalized attacks.” This considerably increases the chances of success, as the victim perceives the contact as legitimate.

But how do they get that information? Zeballos explains it can come from data breaches of public or private companies, where names, ID numbers, emails, or phone numbers are exposed; from public information available on social networks; from the buying and selling of databases on underground forums and dark web markets; or even from previous phishing campaigns, where criminals obtained partial data and later reused it.

Calls pretending to come from banks or telecommunications companies are often the first step to gain the victim’s trust.
Calls pretending to come from banks or telecommunications companies are often the first step to gain the victim’s trust.
/ Pixabay

Today attackers no longer only seek the user to provide their credentials on a fake website. It is increasingly common that they try to convince their victims to install an apparently harmless application that actually contains malware. This strategy gives them much broader access to the device and allows them to maintain control for longer without depending on new user interactions.

WATCH: WhatsApp usernames raise alerts for identity theft risk

This evolution represents an important change from traditional phishing, as before the attack ended when the victim entered their data on a fraudulent site. Today the phone becomes the main target. Once the device is compromised, criminals can monitor user activity, intercept sensitive information, and wait for the right moment to execute financial fraud,” Seminario assures.

Read more Earthquake in Colombia TODAY, Sunday, August 9: exact time, epicenter, and magnitude according to the SGC

The specialist adds that current campaigns respond to schemes developed, in many cases, outside the country and later adapted to the local market. “Families like FluBot and TeaBot have evolved to quickly adjust to different markets, changing the language, the apps they impersonate, and the target financial institutions according to the region where they operate,” he explains.

This model allows cybercriminals to reuse the same infrastructure and malicious code, only changing the bait used to convince victims. Therefore, a campaign that initially affects one country can quickly spread to others through small modifications in messages or fake apps they distribute.

Although each market has different characteristics, there is a global trend: the growth of malware targeting Android devices and the increase of campaigns combining social engineering with banking trojans. This shows that mobile fraud no longer responds to isolated incidents but to increasingly organized, scalable operations capable of quickly adapting to new regions.

Banking trojans can intercept credentials, authentication codes, and other confidential information stored on the cell phone.
Banking trojans can intercept credentials, authentication codes, and other confidential information stored on the cell phone.
/ Unsplash

The future of digital scams

How far can the complexity of these attacks go? As everyday technologies like artificial intelligence become widespread, cybercriminals also begin to incorporate them into their operations.

Zeballos believes that AI is already enabling scams to be more personalized, faster, and harder to detect. In the coming years, he warns, it will be increasingly common to receive calls with cloned voices that imitate family members, bank executives, or public officials.

Chatbots capable of holding long conversations via WhatsApp or phone, answering questions in real time, and adapting their speech to gain the victim’s trust could also proliferate. Added to this would be fake videos or deepfakes of authorities, journalists, or representatives of financial entities promoting fraudulent investments or requesting urgent actions.

Another trend will be hyper-personalized phishing, where each message includes specific information about the victim obtained from data breaches, social networks, or previous campaigns. This will allow criminals to generate thousands of different communications and reduce the signs that traditionally helped recognize a scam.

This represents an important change: before, the user could identify a scam by spelling errors or poorly written messages. With AI, those errors practically disappear,” warns the ESET specialist.

Therefore, he adds, the main defense will no longer be detecting a “badly made” message but always verifying any communication through an official channel and distrusting urgent requests for money, passwords, or app installations.

How to protect yourself

In this scenario, the consulted specialists agree that prevention remains the best tool to avoid becoming a victim. A first warning sign is to distrust any bank, phone operator, or company that requests installing applications via APK files sent by WhatsApp, SMS, email, or external links. Legitimate entities do not use those channels to distribute apps or perform system updates.

WATCH: Cybersecurity: credential theft consolidates as one of the main attack vectors against companies

If, despite this, the user installs the malicious file, the speed of response can make the difference between an attempted fraud and a financial loss. Experts recommend immediately disconnecting the phone from the Internet by disabling mobile data and Wi-Fi connection to prevent the malware from continuing to send information to attackers or receiving new instructions.

The next step is to immediately contact the financial institution to temporarily block accounts or cards that may be compromised. Also, all passwords should be changed from another device considered secure, as doing so from the infected phone could expose the credentials again.

They also advise performing a full scan of the device with a reliable security solution. If there is evidence that the malware remains active or it is not possible to guarantee the device is clean, the safest measure is to reset it to factory settings before reinstalling banking apps or entering confidential information.

Finally, specialists warn that one of the most common mistakes is thinking that just deleting the malicious app is enough. If the malware has already captured credentials or authentication codes, the damage may have occurred before uninstallation. Continuing to use the phone without verifying it is completely free of the threat could allow attackers to maintain access to the user’s information.

Read more He scored a goal, jumped over a fence, and ended up injured: the unusual scene left by Jacy Maranhao in the Brasileirao | VIDEO

YOU MAY BE INTERESTED
  • They discover the first atmosphere on an Earth-like planet in the habitable zone of a distant star
  • How likely is it that something will happen when you are told it is likely to happen
  • How to protect your hearing from harmful noises: “Once lost, it does not recover”
  • Apollo 11: the Moon jump that changed Earth’s history turns 57 years old

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *