Begin typing your search...

CloudSEK identifies new WhatsApp e-challan scam

It has infected more than 4,400 devices and led to fraudulent transactions exceeding Rs. 16 lakh by just one scam operator: Report

image for illustrative purpose

CloudSEK identifies new WhatsApp e-challan scam
X

18 July 2024 8:00 AM IST

Bengaluru: A highly technical Android malware campaign by Vietnamese hackers is targeting Indian users through fake traffic e-challan messages on WhatsApp, according to a report on Wednesday.

Researchers from CloudSEK, a cybersecurity firm, identified the malware as part of the Wromba family.

It has infected more than 4,400 devices and led to fraudulent transactions exceeding Rs. 16 lakh by just one scam operator, they said.

"Vietnamese threat actors are targeting Indian users by sharing malicious mobile apps on the pretext of issuing vehicle challan on WhatsApp,” said Vikas Kundu, Threat Researcher, CloudSEK.

Scammers are sending fake e-challan messages impersonating the Parivahan Sewa or Karnataka Police and tricking people into installing a malicious app.

The app steals personal information and also facilitates financial fraud.

Clicking the link within the WhatsApp message would lead to the download of a malicious APK disguised as a legitimate application.

Once installed, the malware requested excessive permissions, including access to contacts, phone calls, SMS messages, and the ability to become the default messaging app.

It then intercepts OTPs and other sensitive messages, which enables attackers to log in to victims' e-commerce accounts, purchase gift cards, and redeem them without leaving a trace.

Kundu explained that once the app gets installed, it extracts all the contacts to scam more users.

Further, all the SMSes will be “forwarded to the threat actors thus allowing them to log in to various e-commerce and financial apps of the victim,” he added.

Android Malware Cybersecurity Threat Malicious Apps E-challan Scam Financial Fraud OTP Theft Phishing Attack Vietnamese Hackers Indian Users WhatsApp Scam 
Next Story
Share it