Sophisticated WhatsApp Scam Targets Bank Users: Union Bank Aadhaar Update APK Exposes New Cyber Threat

2 hours ago 1

   

| Published: Thursday, November 28, 2024, 17:57 [IST]

There's an increase in concern over fraudulent APKs, particularly those claiming to be from a reputed bank that offers Aadhaar update services. One such recent incident involving a so-called 'Union Bank Aadhar Update' APK is being distributed via WhatsApp with the potential to harvest user information and steal money.

Unlike most common schemes that merely redirect SMS messages to get access to One-Time Passwords (OTPs), this operation showcased a higher level of complexity, and most users might end up giving their personal data to scammers, leading to financial losses.

Union Bank Aadhaar Update APK Exposes New Cyber Threat

The fraudulent application lured victims with a counterfeit bank interface that looked very legit, prompting them to input their date of birth and bank account credentials. These details were then transmitted to an external server.

Subsequently, the command and control (C&C) center dispatched a message, initiating the SMS forwarding mechanism. This setup allowed attackers to orchestrate password reset attempts, capturing the OTPs sent to the victim's phone to gain unauthorized access.

The discovery of this advanced scam was shared by a user identified only as Rithwik Jayasimha, who received the malware-laden APK via a message on WhatsApp. The APK, deceitfully named 'Union Bank Aadhar Update,' aimed to exploit unsuspecting individuals.

Upon closer inspection using jadx, a tool for decompiling Android apps, Jayasimha found out that this operation was far from a simple SMS forwarding scam. The methodology employed by the attackers demonstrated a significant leap in technical ingenuity compared to other SMS-stealing frauds encountered in the past.

To illustrate the complexity and novelty of this scam, a comparison was drawn between it and another SMS-stealing scheme received in July.

In essence, the emergence of such sophisticated fraudulent APKs, particularly those masquerading as Aadhaar update tools, underscores a worrying trend. These schemes not only compromise personal information by masquerading as legitimate services but also employ advanced tactics to bypass security measures.

As these threats continue to evolve, it's crucial for individuals to exercise caution, particularly when downloading applications and responding to unsolicited messages claiming to offer banking or identification update services.

Best Mobiles in India

  • Samsung Galaxy S24 Ultra

    1,29,999

  • HONOR X9b

    22,999

  • OnePlus 12

    64,999

  • Samsung Galaxy S24 Plus

    99,999

  • realme 12 Pro Plus 5G

    29,999

  • OPPO Reno11 Pro 5G

    39,999

  • Vivo X100

    63,999

  • Apple iPhone 15 Pro Max

    1,56,900

  • Samsung Galaxy S23 Ultra

    96,949

  • Apple iPhone 14 Pro Max

    1,39,900

  • Apple iPhone 14 Pro

    1,29,900

  • Apple iPhone 14

    79,900

  • Apple iPhone 13

    65,900

  • Samsung Galaxy A14 4G

    12,999

  • Samsung Galaxy S23 Ultra

    96,949

  • Samsung Galaxy A14 5G

    16,499

  • Samsung Galaxy A54 5G

    38,999

  • Samsung Galaxy A34 5G

    30,700

  • Apple iPhone 11

    49,999

  • ZTE nubia Focus Pro

    19,999

  • ZTE nubia Focus

    17,970

  • ZTE nubia Neo 2

    21,999

  • ZTE nubia Music

    13,474

  • iQOO Z9x

    18,999

  • Tecno Camon 30 Pro 5G

    22,999

  • Tecno Camon 30 5G

    19,999

  • Tecno Camon 30

    17,999

  • Tecno Camon 30 Premier 5G

    26,999

  • TCL 501

    5,999

Story first published: Thursday, November 28, 2024, 17:57 [IST]

Read Entire Article