logo

Basket of Bank Trojans Defraud Citizens of East India

ID: e9387b90-c149-5c3a-9c4b-0624a4c9a0fe

STIX ID: report--e9387b90-c149-5c3a-9c4b-0624a4c9a0fe

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-02-06

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers observed a large-scale Android banking malware campaign—dubbed "FatBoyPanel"—targeting users across India (notably West Bengal, Bihar, and Jharkhand) via malicious APKs distributed over WhatsApp; the fake apps impersonate major banks to collect mobile banking credentials, card numbers, ATM PINs, PAN and Aadhaar details, and intercept SMS OTPs (redirecting them to attacker-controlled numbers or a Firebase C2). The malware uses packing and obfuscation, abuses Android accessibility services for stealthy installation and persistence, requests broad permissions to resist uninstallation, and is associated with roughly 900 samples and about 1,000 phone numbers concentrated in eastern India.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.