{"id":5631,"date":"2025-07-25T10:03:38","date_gmt":"2025-07-25T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/malicious-android-apps-mimic-as-popular-indian-banking-apps-steal-login-credentials\/"},"modified":"2025-07-25T10:03:38","modified_gmt":"2025-07-25T10:03:38","slug":"malicious-android-apps-mimic-as-popular-indian-banking-apps-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/malicious-android-apps-mimic-as-popular-indian-banking-apps-steal-login-credentials\/","title":{"rendered":"Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials"},"content":{"rendered":"<p>    Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Attackers are weaponizing India\u2019s appetite for mobile banking by circulating counterfeit Android apps that mimic the interfaces and icons of public-sector and private banks.<\/p>\n<p>Surfacing in telemetry logs on 3 April 2025, the impostors travel through <a href=\"https:\/\/cybersecuritynews.com\/smishing-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">smishing<\/a> texts, QR codes and search-engine poisoning, tricking users into sideloading the packages.<\/p>\n<p>During the initial execution window, a lightweight dropper decrypts and writes its true payload to external storage before prompting Android\u2019s installer via a forged update dialog.<\/p>\n<p>Cyfirma analysts <a href=\"https:\/\/www.cyfirma.com\/research\/android-malware-posing-as-indian-bank-apps\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that more than 7,000 devices attempted to contact the same Firebase Cloud Messaging (FCM) endpoint within 48 hours of discovery, underscoring the campaign\u2019s reach.<\/p>\n<p>Permission abuse is central to the scheme. REQUEST_INSTALL_PACKAGES bypasses Play Protect, READ_SMS captures OTPs, and QUERY_ALL_PACKAGES gives the trojan a panoramic view of installed apps, laying groundwork for overlay attacks.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiX_niu3rByDy2vdxfmo1XWxQtiQYM9InDCOQC7xL3npXs1CWBQ6iGwjUnp4DWxQJLZVCCYNJ7aWT79u373QGdN9kLJpiBWcU4kJoVkXzz_as2WLHv9qa5-GTLjapVIBCLqu7snOiUMxEDjIIyzygcgTu66C9iaPcZ5Yzuvsk9chQNwBBhExfxL6hHSsq4\/s16000\/Silent%2520Main%2520APK%2520Installer%2520%28Source%2520-%2520Cyfirma%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Silent Main APK Installer (Source \u2013 Cyfirma)<\/figcaption><\/figure>\n<\/div>\n<p>This installer shows the deceptive UI that harvests phone numbers, 4-digit MPINs and 3-digit CVVs which are instantly uploaded to a private Firebase Realtime Database.<\/p>\n<p>Once credentials are secured, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> quietly diverts voice verification by issuing the USSD string *<em>21<\/em>attackerNumber#, enabling unconditional call forwarding.<\/p>\n<p>Persistence is obtained through a BOOT_COMPLETED receiver and the REQUEST_IGNORE_BATTERY_OPTIMIZATIONS flag, allowing the process to survive both reboots and aggressive power-management routines.<\/p>\n<p>Security teams warn that such tactics can facilitate full account takeover in minutes.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>The dropper hides its secondary <a href=\"https:\/\/cybersecuritynews.com\/beware-fake-sbi-reward-apk-attacking-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">APK<\/a>, app-release.apk, in the assets directory and installs it silently through FileProvider.<\/p>\n<p>The core logic fits in a few lines of Kotlin:-<\/p>\n<pre class=\"wp-block-code\"><code>val apk = File(filesDir, \"app-release.apk\")\nassets.open(\"app-release.apk\").copyTo(apk.outputStream())\nval uri = FileProvider.getUriForFile(this, \"$packageName.provider\", apk)\nstartActivity(Intent(Intent.ACTION_VIEW).apply{\n    setDataAndType(uri,\"application\/vnd.android.package-archive\")\n    addFlags(Intent.FLAG_GRANT_READ_URI_PERMISSION); putExtra(\"INSTALL_NOW\", true)\n})<\/code><\/pre>\n<p>If INSTALL_NOW executes without user oversight, PackageInstaller proceeds and the new payload masks itself by declaring only an INFO category activity\u2014no launcher icon appears.<\/p>\n<p>On boot, AutostartHelper reenables services, while a SubscriptionManager call maps active SIM slots to numbers, ensuring every intercepted SMS is tagged with the correct sender before JSON <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-data-exfiltration-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">exfiltration<\/a> through FCM.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Experience faster, more accurate phishing detection and enhanced protection for your business with real-time sandbox analysis-&gt;\u00a0<strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=article&amp;utm_campaign=freemium-exclusive&amp;utm_content=plans1&amp;utm_term=220725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/malicious-android-apps-mimic-as-popular-indian-banking-apps\/\">Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/malicious-android-apps-mimic-as-popular-indian-banking-apps\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials Attackers are weaponizing India\u2019s appetite for mobile banking by circulating counterfeit Android apps that mimic the interfaces and icons of public-sector and private banks. Surfacing in telemetry logs on 3 April 2025, the impostors travel through smishing texts, QR codes and search-engine poisoning, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5631","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5631"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5631"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5631\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5631"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5631"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5631"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}