Fake Armenian Government “Cashback App” Identified as Scamware

December 16, 2025

A malicious Android application named ArmScan.apk was distributed via the domain gov-am.sbs, impersonating a government-backed financial support tool. The app was promoted as an invoice scanning / cashback application, a theme designed to exploit public trust and financial motivation. The WHOIS lookup for the domain shows connection to Malaysia.

Social Engineering
The landing page claimed users could scan purchase invoices and receive government cashbacks — a believable narrative aligned with public expectations around subsidy or tax refund programs.

Virustotal classifies it as  malicious (low severity), since the apk was detected by Google’s spam and threat filtering engines. Several Antivirus Engines hav clasified it as a Trojan/Dropper, meaning the app can infiltrate data from a user’s phone, as well as download additional scam modules.

User Protection Guidance

1️⃣ Avoid APK Downloads
Install apps only from Google Play.

2️⃣ Verify Government Claims
Check official .gov.am domains.

3️⃣ Treat Cashback/Subsidy Promises with Suspicion

4️⃣ Never Enter Financial Credentials into Unknown Apps

5️⃣ Disable “Install from Unknown Sources”