Basket of Bank Trojans Defraud Citizens of East India
ID: e9387b90-c149-5c3a-9c4b-0624a4c9a0fe
STIX ID: report--e9387b90-c149-5c3a-9c4b-0624a4c9a0fe
Feed Name: Dark Reading
Researchers observed a large-scale Android banking malware campaign—dubbed "FatBoyPanel"—targeting users across India (notably West Bengal, Bihar, and Jharkhand) via malicious APKs distributed over WhatsApp; the fake apps impersonate major banks to collect mobile banking credentials, card numbers, ATM PINs, PAN and Aadhaar details, and intercept SMS OTPs (redirecting them to attacker-controlled numbers or a Firebase C2). The malware uses packing and obfuscation, abuses Android accessibility services for stealthy installation and persistence, requests broad permissions to resist uninstallation, and is associated with roughly 900 samples and about 1,000 phone numbers concentrated in eastern India.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
