logo

Indian Banking Customers Fall for SMS Scams

ID: e769dd74-d027-5110-907f-d3d2659d0628

STIX ID: report--e769dd74-d027-5110-907f-d3d2659d0628

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz observed active SMS-based phishing campaigns targeting customers of major Indian banks (HDFC, Axis, SBI) that distribute Android malware via fake card-update and KYC pages; the malware harvests card details and personal data through in-app or remote-rendered phishing pages, requests SMS permissions to intercept OTPs, exfiltrates data to command-and-control servers, employs cloaking to avoid repeat display, and the report includes multiple IOCs (domains and MD5 hashes) and detection notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.