logo

Cyberattackers Use Fake RTO Challan Alerts to Spread Android Malware

ID: e5aec770-ecac-5888-8ae2-176742a83d78

STIX ID: report--e5aec770-ecac-5888-8ae2-176742a83d78

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-02-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Seqrite Labs discovered a sophisticated Android malware campaign impersonating RTO challan notifications distributed via WhatsApp that uses a three-stage modular architecture: an initial dropper with a cryptominer, a persistence/backend-initialization stage using Firebase, and a final data-theft/surveillance stage that prompts victims for high-risk permissions. The campaign exfiltrates OTPs, banking credentials, Aadhaar/PAN details, and other sensitive data to attacker-controlled servers, enables remote C2 operations (including SMS forwarding and tracking), infected roughly 7,400 devices, and facilitates large-scale financial fraud and identity theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.