logo

Attackers Mimic RTO Challan Notifications to Deliver Android Malware

ID: 9b203bd5-486c-573b-8c5a-21eb9ec44123

STIX ID: report--9b203bd5-486c-573b-8c5a-21eb9ec44123

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

An active Android malware campaign is distributing sideloaded fake Regional Transport Office (RTO) "E-Challan" apps via WhatsApp and SMS to Indian users; the multi-stage malware leverages social engineering, requests dangerous permissions, implements anti-analysis techniques and a custom VPN tunnel to harvest banking messages, OTPs, and personal metadata, maintain persistence, and enable large-scale financial fraud and identity theft. Users are advised to avoid installing apps outside official stores and verify fines via official government websites, while organizations should deploy mobile threat defense and security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.