logo

Shielding Against Android Phishing in Indian Banking

ID: 4a5cfa84-e74e-568f-9aeb-c649dca5a621

STIX ID: report--4a5cfa84-e74e-568f-9aeb-c649dca5a621

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2023-12-20

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This report analyzes Android/Banker.AFX, a banking trojan distributed via WhatsApp lures that presents a fake KYC app to Indian users, collects PII (name, DOB, Aadhar, PAN, CIF, account and card details), requests SMS read permission to intercept OTPs, and exfiltrates data using Firebase (wss://s-usc1a-nss-2003.firebaseio.com). The blog provides static analysis (permissions, package hello.uwer.hello.hello.google.is.the.best), sample hashes, telemetry (McAfee detections), indicators of compromise, and recommended mitigations such as avoiding third-party APKs and using mobile security solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.