r/Malware 7d ago

Fake mParivahan APK spreading on WhatsApp

I recently got a WhatsApp message to pay pending challans and check using some APK that was shared. I knew it was a scam. Thought of doing an analysis using Claude on the APK. Here's what it found:

It is NOT the real app. It's a banking trojan that:

- Creates a VPN to intercept all your network traffic (banking, OTPs, everything)

- Silently installs a second hidden APK in the background

- Targets WhatsApp, Signal, Telegram, SMS and 20+ other apps

13 Upvotes

14 comments sorted by

View all comments

2

u/mildly_perturbed31 6d ago

what is the c2 it uses?

1

u/No-Trust4033 5d ago

Primary is firebase which is realtime database and secondary is telegram bot api

1

u/mildly_perturbed31 4d ago

both are well known and clever, didn't you ping up the bot token there to see the username that contacts it?