logo

Indian Vehicle Owners Warned as Browser-Based e-Challan Phishing Gains Momentum

ID: b619b35d-ec23-50f7-a67f-50ff9379db8d

STIX ID: report--b619b35d-ec23-50f7-a67f-50ff9379db8d

Feed Name: The Cyber Express

Threat Score
60/100

Date Published: 2025-12-24

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A renewed RTO-themed e-challan phishing campaign is targeting Indian vehicle owners by sending unsolicited SMS messages with deceptive links to fraudulent government-branded portals. The pages fabricate challan records to create urgency and collect full card details on attacker-controlled payment pages (no official gateway), indicating financial theft. Infrastructure analysis links multiple phishing domains and IPs (notably 101.33.78.145 and 43.130.12.41) used across verticals, showing reusable, scalable fraud infrastructure and automated domain rotation to evade takedowns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.