Published on: July 26, 2025
By: CyberDudeBivash Editorial Team
Website:cyberdudebivash.com
In 2025, threat actors have significantly scaled campaigns impersonating Indian public and private banking apps. According to Cyfirma telemetry, attackers exploited smishing (SMS phishing), malicious QR codes, and search-engine manipulation to distribute counterfeit Android APKs. Once installed, these malware apps mimicked legitimate banking UIs and promptly harvested user credentials.(turn0search1)
Additionally, call-forwarding via USSD (e.g., *21attackerNumber#
) redirects verification calls to the attacker, enabling full account takeover. A BOOT_COMPLETED receiver and battery-optimization bypass ensure persistence and launch on startup.
Trojan / Campaign | Modus Operandi | Targets / Impact |
---|---|---|
New Fake Indian Bank Malware | Smishing, QR code malware, fake update UIs, Firebase exfil | Credentials, OTP theft, call forwarding |
Drinik Trojan | Fake tax/KYC apps, screen recording, overlay attacks | Targets 18 Indian banks; steals OTP/CVVβturn0search2 |
SOVA Trojan | Screen overlays, keylogging, crypto wallet targeting | Targets 200+ apps in India (turn0search0) |
Avoid installing APKs received via WhatsApp, SMS, or through search-engine links. Trust only official apps from Google Play Store.
Disallow SMS access, installation privileges, and battery-optimization exemptions unless strictly necessary.
Keep Google Play Protect active and install reputable mobile security apps to detect known trojans like Android/Banker.AXF!ML.(turn0search8)
Watch for apps requesting persistent access, hiding their icons, or performing unexpected USSD or SMS activity.
If possible, use stronger authentication methodsβbiometric, hardware keysβand monitor account activity closely.
Report suspected fraud to banks and register complaints via portals like Indiaβs cybercrime.gov.in or local cyber police.
βFake banking apps in India have evolved from phishing screens to side-loaded malware with deep persistence. SOVA, Drinik, and now these counterfeit bank apps build a potent combo designed for financial theft.β β Cybersecurity Analysts at Cyfirma and McAfeeβ(turn0search1, turn0search4, turn0search5)
Have you encountered suspicious APKs or messages claiming to be from your bank?
Share experiences and tips in the comments, or tweet us at @CyberDudeBivash.
Subscribe to our Cyber Magazine for ongoing coverage on mobile threats, phishing campaigns, and real-time cyber defense strategies.
Tags: #AndroidMalware #BankingTrojan #Smishing #FakeBankApp #IndianBanks #OTPHeist #CredentialTheft #Cybersecurity #CyberDudeBivash