City
Epaper

Vietnamese hackers fuelling WhatsApp e-challan scam in India: Report

By IANS | Updated: July 17, 2024 13:45 IST

Bengaluru, July 17 A highly technical Android malware campaign by Vietnamese hackers is targeting Indian users through fake ...

Open in App

Bengaluru, July 17 A highly technical Android malware campaign by Vietnamese hackers is targeting Indian users through fake traffic e-challan messages on WhatsApp, according to a report on Wednesday.

Researchers from CloudSEK, a cybersecurity firm, identified the malware as part of the Wromba family.

It has infected more than 4,400 devices and led to fraudulent transactions exceeding Rs. 16 lakh by just one scam operator, they said.

"Vietnamese threat actors are targeting Indian users by sharing malicious mobile apps on the pretext of issuing vehicle challan on WhatsApp,” said Vikas Kundu, Threat Researcher, CloudSEK.

Scammers are sending fake e-challan messages impersonating the Parivahan Sewa or Karnataka Police and tricking people into installing a malicious app.

The app steals personal information and also facilitates financial fraud.

Clicking the link within the WhatsApp message would lead to the download of a malicious APK disguised as a legitimate application.

Once installed, the malware requested excessive permissions, including access to contacts, phone calls, SMS messages, and the ability to become the default messaging app.

It then intercepts OTPs and other sensitive messages, which enables attackers to log in to victims' e-commerce accounts, purchase gift cards, and redeem them without leaving a trace.

Kundu explained that once the app gets installed, it extracts all the contacts to scam more users.

Further, all the SMSes will be “forwarded to the threat actors thus allowing them to log in to various e-commerce and financial apps of the victim,” he added.

Using proxy IPs, the attackers avoid detection and maintain a low transaction profile.

Using the malware, attackers have accessed 271 unique gift cards, conducting transactions worth Rs 16,31,000, according to the report.

Gujarat has been identified as the most affected region, followed by Karnataka.

To protect against such malware threats CloudSEK urged users to stay vigilant and adopt security best practices installing apps only from trusted sources like Google Play Store; limiting app permissions and regularly reviewing them, maintaining updated systems, and enabling alerts for banking and sensitive services.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

NationalCentre clarifies: Siddaramaiah was invited, asked to preside over Sigandur event

National‘Break silence’: BJP’s Amit Malviya jabs Congress chief on drug taint of son’s aide

BusinessBook Your Andaman Tour Packages With andamanbliss.com - Customize Your Packages As Per You Like

BusinessGramik - A Peer Commerce Platform Agritech Startup Raises ₹17 Cr in Bridge Round Ahead of ₹56 Cr Series A Fundraise

MumbaiMumbai: Complaint Filed Against MNS Chief Raj Thackeray Over His Remarks at 'Marathi Pride' Rally

Business Realted Stories

BusinessOver 9 in 10 Indian youth wish to apply for global jobs if given free visa: Report

BusinessSattvik Certifications Launches Mobile App in Southeast Asia to Empower Ethical Consumption

BusinessSattvik Certifications Launches Mobile App in Southeast Asia to Empower Ethical Consumption

BusinessAI 171 crash preliminary report has found no mechanical or maintenance faults: Air India CEO

BusinessInstitutional confidence in Paytm continues to strengthen: Domestic MFs, FPIs raise stake