New Android Banking Malware Targets Indian Customers Through Fake Banking Apps

Abstract digital illustration of a pen writing on a digital surface.

A sophisticated Android malware campaign targeting Indian banking customers has been discovered, involving counterfeit banking applications designed to compromise user credentials and facilitate unauthorized transactions. The discovery comes amid a dramatic 260 percent surge in mobile banking malware attacks globally, with India being a primary target market for cybercriminals.

The malware uses a modular architecture consisting of a dropper and main payload to infiltrate devices and steal sensitive information. The approach is similar to recent threats like the Tria Stealer malware, which employs comparable techniques to compromise banking applications.

The malware’s dropper component leverages multiple Android permissions to establish persistence, including REQUEST_INSTALL_PACKAGES for silent installation of secondary packages, ACCESS_NETWORK_STATE for monitoring connectivity, and QUERY_ALL_PACKAGES to identify and target banking applications. The main payload requests permissions to intercept SMS messages, enabling the capture of one-time passwords and two-factor authentication codes used in banking security. The SMS interception capability is particularly concerning as India’s Department of Telecommunications has recently launched initiatives to combat such mobile fraud techniques.

The malicious applications deploy sophisticated phishing interfaces that replicate legitimate banking user interfaces. The malware uses Firebase infrastructure for command-and-control operations, enabling remote command execution and persistent device control. To maintain stealth, the malware implements hidden launcher activities and silent installation mechanisms, making it particularly difficult for users to detect.

Technical capabilities of the malware include SMS interception and exfiltration, debit card data collection, call forwarding manipulation, remote command execution, and battery optimization bypasses to ensure continuous background operation. The malware is distributed through multiple vectors, including SMS messages, QR codes, and search engine optimization techniques. The use of QR codes as an attack vector matches patterns seen in recent “Scanception” phishing campaigns that specifically target mobile users.

“The malware’s use of social engineering, permission exploitation, and persistent behaviors poses significant threats to mobile banking security,” notes CYFIRMA’s analysis.

The discovery underscores the importance of verifying application authenticity and installing applications exclusively from official sources. Banking institutions and security professionals are implementing enhanced detection mechanisms and user education programs to address such sophisticated malware campaigns. The response comes as Indian authorities implement new mobile number validation rules and other security measures to combat the rising tide of cyber fraud in the financial sector.

Sources: CYFIRMA, GBHackers, Cybersecurity News, AMPCUS Cyber