
Security researchers are warning Android users about a malicious app, Mobdro Pro IP TV + VPN, which poses as a free IPTV streaming and VPN service but installs dangerous malware capable of stealing banking credentials.
The app, discovered by researchers at Cleafy, is not a legitimate VPN. It delivers Klopatra, a new Android banking Trojan and remote-access tool that is not linked to any previously known malware families. Once installed, Klopatra allows attackers to take full control of the device, access sensitive data, and carry out fraudulent transactions.
According to researchers, Klopatra uses a sophisticated infection chain that combines social engineering and technical exploits:
The researchers explain:
“Klopatra’s effectiveness lies in a carefully orchestrated infection chain, which begins with social engineering and culminates in complete device takeover.”
VPNs are widely used to protect privacy, bypass geo-restrictions as well as secure internet traffic. However, not all VPNs on Google Play are safe. The VPN Transparency Report 2025 by the Open Technology Fund highlighted concerns with several widely-used apps, including Turbo VPN, VPN Proxy Master, XY VPN, and 3X VPN – Smooth Browsing, each downloaded over 100 million times.
Some of these apps use protocols like Shadowsocks, which are not designed for privacy, giving users a false sense of security. The report stresses the importance of checking app ownership, technology, and privacy practices before installation.
Security experts recommend the following steps for Android users:
If a device is suspected to be infected:
Researchers emphasize that careful selection of VPNs and streaming apps is crucial for maintaining security and protecting sensitive financial information.