logo

Android Malware Campaign Targets Indian Users via Fake eChallan Alerts

ID: d4787801-b1b8-5053-8ab2-44eb156c3979

STIX ID: report--d4787801-b1b8-5053-8ab2-44eb156c3979

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-03-20

Date Updated: 2026-05-05

Author: Ashish Khaitan

...
...

An ongoing campaign targets Indian vehicle owners using SMS lures masquerading as eChallan/RTO alerts, delivering malicious APKs (e.g., "RTO Challan.apk", "MParivahan.apk") that act as droppers and later hide while requesting sensitive permissions (SMS, calls, background activity, VPN) to maintain persistence and intercept traffic. Parallel browser-based phishing clones official portals to generate fake challans and harvest card details and credentials via fake payment pages; investigators found shared backend infrastructure with dozens of phishing domains and IP indicators such as 101.33.78.145 and 43.130.12.41.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.