RTO Challan Fraud: A Technical Report on APK-Based Financial and Identity Theft
Essential information
- Published
- 12/12/2025 10:09
- Modified
- 21/12/2025 19:01
- Tags
- 2025-12-12 android apk e-challan financial fraud identity theft otp interception rto challan / e-challan social engineering vpn abuse whatsapp
- Related entities
- 2 observables, 3 techniques (mitre), 1 malware, 5 others
Description
A sophisticated mobile fraud operation has been uncovered, distributing a malicious 'RTO Challan / e-Challan' Android application via WhatsApp. The APK uses advanced obfuscation and hidden installation techniques to establish persistent control over victims' devices. It creates a custom VPN tunnel to mask network activity and harvests extensive personal, device, and financial information. The malware intercepts OTPs, manipulates call behavior, and presents a fraudulent payment interface to steal banking credentials. Analysis of the C2 infrastructure revealed obfuscated Base64-encoded URLs pointing to malicious domains. The campaign combines mobile malware, financial fraud, and social engineering, posing a high-risk threat capable of severe monetary losses and large-scale exposure of sensitive personal data.