Shadow Banking in Your Pocket: Exposing Android App Used by Money Mules
ID: ce752e13-42bb-51b1-8519-fcd8ae12e5fe
STIX ID: report--ce752e13-42bb-51b1-8519-fcd8ae12e5fe
Feed Name: CloudSEK Blog
Threat Score
**Executive summary:** CloudSEK's investigation exposes XHelper, a malicious APK and associated ecosystem used by organized cybercriminals to recruit, train, and manage hundreds of thousands of money mule accounts in India; the platform automates onboarding, order assignment, OTP/ SMS-forwarding workarounds, and rapid transfers to high-limit corporate accounts before converting funds to USDT, causing substantial financial, operational, and reputational risk to banks and victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
