Android Malware Campaign Targets Indian Users via Fake eChallan Alerts
ID: d4787801-b1b8-5053-8ab2-44eb156c3979
STIX ID: report--d4787801-b1b8-5053-8ab2-44eb156c3979
Feed Name: The Cyber Express
An ongoing campaign targets Indian vehicle owners using SMS lures masquerading as eChallan/RTO alerts, delivering malicious APKs (e.g., "RTO Challan.apk", "MParivahan.apk") that act as droppers and later hide while requesting sensitive permissions (SMS, calls, background activity, VPN) to maintain persistence and intercept traffic. Parallel browser-based phishing clones official portals to generate fake challans and harvest card details and credentials via fake payment pages; investigators found shared backend infrastructure with dozens of phishing domains and IP indicators such as 101.33.78.145 and 43.130.12.41.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
