Fraudsters have created a fake version of ‘Diy’ and are tricking Ukrainians into installing an APK file

Katerina Melnychenko
Katerina Melnychenko Deputy Editor-in-Chief
Fraudsters have created a fake version of ‘Diy’ and are tricking Ukrainians into installing an APK file
Users see a familiar design, logo and the name ‘Dii’, so they may not immediately spot the fake.
A new phishing scam has been uncovered in Ukraine, involving a fake website masquerading as “Dія.BankID”. The cybercriminals have copied the interface of the government service and are prompting users to install a malicious APK file on their smartphones.

The Brama project has reported on the scam. The official “Diya” portal also reminds users that government services are available via the official website diia.gov.ua, and that the app should only be downloaded from official app stores.

A new phishing scam has been detected in Ukraine, in which fraudsters are posing as the government service “Diya.BankID”.

The attackers have created a fake webpage that visually mimics the interface of “Dii” and BankID. The aim of the scam is to trick users into downloading a third-party file onto their smartphone and gaining access to their personal data.

The main sign of a fake is the website address. The official “Diya” portal operates on the domain diia.gov.ua. If the page has a different extension or a similar but unofficial address, it may be a phishing site.

How the scam works

The fake website does not redirect the user to Google Play or the App Store.

Instead, the page offers to download the file directly from the browser. In the reported scam, the file had the .apk extension, specifically with a name such as client-with...3U2KT.apk.

An APK is an installation file for Android. The format itself is not inherently malicious, but downloading such files from unknown websites poses a serious risk to your smartphone’s security.

What a malicious app can do

Once installed, a suspicious app may request access to SMS messages, notifications, files, contacts or the phone’s internal memory.

Such permissions can allow fraudsters to intercept verification codes, access messages, collect personal data and monitor the user’s actions on the device.

It is precisely through such permissions that attackers can gain access to banking apps, accounts on messaging apps or other services that use SMS or notification-based verification.

How to spot a fake “Diya”

The official “Diya” app should only be installed via Google Play or the App Store.

Government services do not distribute APK files via third-party websites, random links, messaging apps or pages with unknown domains.

If a website asks you to download the app directly from your browser, this is a sign of fraud.

It is also worth checking the page address before logging in. Even if the website looks similar to “Diya”, a fake domain may lead to a phishing page.

What to do if the file has already been installed

If a user has already downloaded or installed a suspicious APK file, it must be deleted immediately.

After that, you should scan your smartphone with antivirus software, change passwords for important services, and check your activity in banking apps.

You should also review the permissions granted to the suspicious app and revoke access to SMS messages, notifications, files and other sensitive data.

If you suspect that fraudsters may have gained access to your accounts, you should contact your bank immediately and block any suspicious transactions.

Why is this dangerous

Phishing that uses the branding of government services relies on trust.

The user sees a familiar design, logo and the name “Dii”, so they may not immediately spot the fake.

Fraudsters use this effect to force people to act quickly: click a button, download a file, grant permissions or enter personal details.

Such schemes can lead to loss of access to bank accounts, theft of personal information, or further attacks via messaging apps and email.

Follow us on Telegram

Share tittle
Society
A car was blown up in a military housing estate near Moscow; the driver was killed
Society

A car was blown up in a military housing estate near Moscow; the driver was killed

A BMW X3 has exploded in the Russian town of Balashikha, near Moscow; the driver has been killed. Russian investigators believe that an explosive device was planted in the car.

09.06.2026
The ‘Izolyatsia’ prison in Donetsk. Human rights activists have gathered evidence of acts that may constitute crimes against humanity
Society

The ‘Izolyatsia’ prison in Donetsk. Human rights activists have gathered evidence of acts that may constitute crimes against humanity

The Ukrainian human rights organisation Truth Hounds has documented dozens of cases of torture, enforced disappearances, sexual violence and unlawful detention at the former ‘Izolyatsia’ art centre in occupied Donetsk, which militants turned into a torture chamber on 9 June 2014.

09.06.2026
The Cabinet of Ministers is set to present a new concept for Ukraine’s pension system
Society

The Cabinet of Ministers is set to present a new concept for Ukraine’s pension system

On 8 June, the Cabinet of Ministers is due to present the concept for the forthcoming pension reform to the coalition council. The Verkhovna Rada expects a review of the pension calculation formula, indexation rules and approaches to special payments.

09.06.2026
The High Anti-Corruption Court has barred AMCU Chairman Kyrylenko from travelling abroad
Society

The High Anti-Corruption Court has barred AMCU Chairman Kyrylenko from travelling abroad

The High Anti-Corruption Court has refused to grant permission for the head of the Antimonopoly Committee, Pavlo Kyrylenko, to travel abroad. The official had planned a trip to Paris to attend an event organised by the Organisation for Economic Co-operation and Development.

09.06.2026
A powerful geomagnetic storm has hit Earth: forecast for 9 June
Society

A powerful geomagnetic storm has hit Earth: forecast for 9 June

A powerful geomagnetic storm was recorded on Earth on 8 June. The Kp index rose to almost 7, corresponding to a strong G3-level geomagnetic storm.

09.06.2026