SUMMARY This is AI generated summarization, which may have errors. For context, always refer to the full article. Albert, a 68-year-old retiree, received a call noon on August 14, 2025. The call came at a perfect time because Albert needed a payment reference number (PRN) from his SSS (social security service) but he was having a challenging time logging on to his app. The caller knew his full name, his SSS number, and his address, and offered to assist him in downloading a supposed updated SSS app. The assistance came in the form of him clicking a link provided over Viber, followed by a very long installation process. In one-and-a-half hours, his three bank accounts and two cash wallets — all connected to his Android phone — were swiped. More than one million pesos in life savings gone. Albert never provided any personal detail like OTPs (one time passwords) or security codes. “My dad was depressed for the first few months,” Albert’s daughter Jobelle Garcia told Rappler. The scam is a banking trojan deployed through malware on Android which can control your device from a remote location, and it has been traced to scam compounds in Cambodia, according to a first-of-its-kind report by US-based cybersecurity firm InfoBlox, and Vietnamese cyber safety non-profit Chong Lua Dao. “We uncovered an Android banking trojan that is likely operated from multiple locations, including the K99 Triumph City compound in Cambodia,” said the report. This is the first time that strong evidence has been found to connect a specific type of malware to a physical location of a scam compound, and it was made possible by trafficked workers who escaped from the compound and took damning evidence with them. The malware The team found a “sophisticated malware-as-a-service (MaaS),” which is a high-end malicious tool sold