logo

Drinik Malware Targets Indian Taxpayers With Upgrades

ID: 3c5d76e5-9727-5e00-ac68-b43d06b4ab42

STIX ID: report--3c5d76e5-9727-5e00-ac68-b43d06b4ab42

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-18

Date Updated: 2026-07-16

...
...

CRIL analysis of the Drinik Android banking trojan documents an active campaign (since 2021) targeting Indian taxpayers and multiple banks; the malware evolved from SMS theft and phishing to advanced capabilities including MediaProjection-based screen recording, keylogging via Accessibility Service, CallScreeningService abuse to block incoming calls, and FCM-driven C2 commands. The report includes technical details of an analyzed APK, IOCs (file hashes, C2 URL and IPs), attack flow (phishing WebView loading genuine tax portal, harvesting biometric PIN and banking credentials), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.