250 Malicious Apps and 80 Phishing Domains Uncovered 
in SarangTrap Campaign
DALLAS, Texas, July 23, 2025 – Zimperium, the world leader in mobile security, announced its zLabs threat research team has uncovered a highly coordinated and emotionally manipulative malware campaign that is targeting mobile users through fake dating and social networking apps. The campaign, identified as SarangTrap, has already leveraged over 250 malicious Android apps and more than 80 phishing domains, all designed to steal sensitive data while masquerading as trusted platforms.
These apps, once installed, request access to contacts, images, and other sensitive data, all while presenting a slick, believable interface that mimics legitimate dating services. Victims have reported being lured in with emotionally charged interactions and exclusive “invitation codes,” only to later face extortion threats after their private information was silently exfiltrated.
“This is more than just a malware outbreak, it’s a digital weaponization of trust and emotion,” said the zLabs research team. “Users seeking connection are being manipulated into granting access to some of their most personal data.”
The campaign is active across both Android and iOS platforms, using deceptive installation methods such as malicious configuration profiles on iOS to gain access to contacts, photos, and device identifiers. Many of the phishing domains were even indexed by popular search engines, making them appear legitimate to unsuspecting users searching for dating or social apps.
Zimperium strongly urges mobile users to:
- Be cautious of apps requiring unusual permissions or invitation codes
- Avoid downloading apps from unfamiliar links or unofficial app stores
- Regularly review device permissions and installed profiles
- Install on‑device mobile security solution to help detect and block malicious apps
For a deep dive into the SarangTrap campaign, including technical analysis, screenshots, and indicators of compromise, read the full blog: Dark Side of Romance
About Zimperium
Zimperium is the world leader in mobile security. Purpose‑built for mobile environments, Zimperium provides unparalleled protection for mobile applications and devices, leveraging AI‑driven, autonomous security to counter evolving threats including mobile‑targeted phishing (mishing), malware, app vulnerabilities and compromise, as well as zero‑day threats. As cybercriminals adopt a mobile‑first attack strategy, Zimperium helps organizations stay ahead with proactive, unmatched protection of the mobile apps that run your business and the mobile devices relied upon by your employees. Headquartered in Dallas, Texas, Zimperium is backed by Liberty Strategic Capital and SoftBank. Learn more at www.zimperium.com.
