216.73.216.6

Beware! Fake 'NextGen mParivahan' Malware Returns

· Published 09/04/2025 17:43 · Modified 09/04/2025 20:40

Export JSON

Essential information

Published
09/04/2025 17:43
Modified
09/04/2025 20:40
Tags
2025-04-09 android anti-analysis c2 extraction dropper-payload firebase malformed apk nextgen mparivahan notification stealer sms theft
Related entities
3 techniques (mitre), 1 malware

Description

A new variant of the fake malware has emerged, exhibiting enhanced stealth and data theft capabilities. The malware, disguised as a government traffic notification system, tricks users into downloading a malicious app that requests extensive permissions. This latest version targets messages from social media, communication, and e-commerce apps, posing a greater threat to user privacy. It employs advanced techniques such as malformed APKs, multi-stage architectures, and dynamic C2 generation to evade detection. The malware steals sensitive data, including SMS messages and notification content, uploading it to or a C2 server. Its ability to access notifications, SMS, and app data significantly risks user privacy, highlighting the need for improved security awareness and analysis tools.

External references