A sophisticated Android malware operation known as GhostBat RAT is targeting Indian users by impersonating official Regional Transport Office (RTO) applications, including the mParivahan app, according to research from Cyble Research and Intelligence Labs (CRIL). The campaign emerges amid India’s broader push toward digital transportation services, including the recent implementation of digital smart card driving licenses.
The malware campaign spreads through WhatsApp messages and SMS containing shortened URLs that appear to be legitimate RTO apps. These links redirect users to GitHub-hosted APKs or compromised websites that distribute malicious Android droppers. The malware employs multi-stage workflows, ZIP header manipulation, and string obfuscation techniques to avoid detection, following similar patterns to the recently discovered banking malware campaigns targeting Indian customers.
After installation, GhostBat RAT deploys phishing pages that mimic government apps like mParivahan to collect sensitive information including mobile numbers, vehicle details, and UPI payment data. The targeting of UPI systems raises particular concerns as India prepares to implement biometric authentication for UPI payments, potentially creating new security challenges.
The malware exfiltrates SMS messages containing banking-related keywords to Command and Control servers and can forward incoming SMS messages for OTP harvesting, similar to techniques observed in the Tria Stealer malware targeting WhatsApp users. Some variants also incorporate cryptocurrency mining capabilities, adding to the growing trend of mobile-based crypto mining malware.
The malware’s device registration process occurs through a Telegram bot called GhostBatRat_bot, which serves as part of its command and control infrastructure. The approach matches recent incidents where Telegram bots have been used to exploit Indian citizens’ personal data. As of September 2025, security researchers have identified more than 40 distinct Android malware samples associated with this campaign.
The technical implementation includes native libraries to dynamically resolve API calls and deploy various payloads. The malware’s sophistication is demonstrated through its use of multiple stages, obfuscation techniques, and diverse functionality including banking credential theft and crypto mining capabilities.
Security researchers recommend that users exercise caution with shortened URLs, carefully manage SMS permissions, and avoid installing applications from untrusted sources. The campaign represents an emerging pattern of mobile attacks that combine social messaging channels with hosted malicious payloads, contributing to the surge in Android phishing threats that has resulted in over 22,800 malicious applications being detected in recent months.
Sources: Security Online, GB Hackers, Cyble