logo

New Android Banking Malware Abuses Fake KYC Workflow and WhatsApp Delivery to Hijack Accounts

ID: ca86c9af-1bff-5b80-bc66-f207b506dae4

STIX ID: report--ca86c9af-1bff-5b80-bc66-f207b506dae4

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Tushar Subhra Dutta

...
...

KYCShadow is an Android banking malware campaign targeting Indian bank customers via WhatsApp-distributed fake KYC apps; it employs a two-stage dropper to silently install a hidden secondary payload that requests SMS/call permissions, intercepts OTPs, registers with Firebase C2, and routes traffic through an attacker-controlled VPN (domains observed include jsonapi.biz), enabling credential theft and persistent remote control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.