Phishing Campaign for Indian Banking Users
ID: 850a3796-7f66-51ae-801c-49e046a2d5e8
STIX ID: report--850a3796-7f66-51ae-801c-49e046a2d5e8
Feed Name: Zscaler Security Research Blog
A phishing campaign impersonating customer support for major Indian banks collects detailed banking credentials via realistic pages and then delivers Android apps (e.g., "SBI Quick Support") that request SMS permissions, persist across reboots, monitor incoming SMS messages (including OTPs), and exfiltrate them to a hard-coded C2; the report provides package names, domains, MD5 hashes, and MITRE technique mappings and advises installing apps only from official stores and disabling unknown sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
