216.73.217.22

RTO Challan Fraud: A Technical Report on APK-Based Financial and Identity Theft

· Published 12/12/2025 10:09 · Modified 21/12/2025 19:01

Export JSON

Essential information

Published
12/12/2025 10:09
Modified
21/12/2025 19:01
Tags
2025-12-12 android apk e-challan financial fraud identity theft otp interception rto challan / e-challan social engineering vpn abuse whatsapp
Related entities
2 observables, 3 techniques (mitre), 1 malware, 5 others

Description

A sophisticated mobile fraud operation has been uncovered, distributing a malicious '' application via . The uses advanced obfuscation and hidden installation techniques to establish persistent control over victims' devices. It creates a custom VPN tunnel to mask network activity and harvests extensive personal, device, and financial information. The malware intercepts OTPs, manipulates call behavior, and presents a fraudulent payment interface to steal banking credentials. Analysis of the C2 infrastructure revealed obfuscated Base64-encoded URLs pointing to malicious domains. The campaign combines mobile malware, , and , posing a high-risk threat capable of severe monetary losses and large-scale exposure of sensitive personal data.

External references