Alpha Cyber

Stopping the Steal: Mapping Infrastructure Behind Fake Indian Banking Apps on Android

Fraudsters are luring users with convincing fake banking apps on Google Play and third‑party stores to harvest login credentials, OTPs, and other sensitive data.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Fake Indian Banking Apps Trojan

Fraudsters are luring users with convincing fake banking apps on Google Play and third‑party stores to harvest login credentials, OTPs, and other sensitive data. Our infrastructure mapping of this campaign reveals how attackers distribute, manage, and profit from these malicious apps, and gives defenders the edge to detect, contain, and block activity before customers are compromised.

Campaign summary

Fake Indian APP Android Banking Trojan Graph

What it does: Fake banking apps impersonate legitimate bank clients to collect credentials and 2FA codes, often pairing a dropper/base payload with a second-stage payload that performs data collection and exfiltration.

How attackers operate:

Malicious apps delivered through official and third‑party stores using social engineering and fake reviews to appear legitimate.
Dropper/base payload installs a secondary/main payload that performs credential harvesting and persistence.
Command channels and distribution points used to push updates and harvest data from infected devices.
Rapid reuse of distribution assets across multiple imitations and regions to maximize yield.

Technical indicators Block and monitor immediately

Integrate the following hashes into your endpoint, mobile security, and network defenses. Add them to IOC feeds, EDR/MDM rule sets, and SIEM correlation rules.

Indicator (SHA256)TypeRemarks
ee8e4415eb568a88c3db36098b7ae8019f4efe565eb8abd2e7ebba1b9fb1347dSHA256Base payload / dropper
131d6ee4484ff3a38425e4bc5d6bd361dfb818fe2f460bf64c2e9ac956cfb13dSHA256Main payload (credential harvesting)

Detection & mitigation guidance

  • Block and quarantine files matching the above hashes at ingestion and execution points.
  • Enforce app‑store hygiene: only permit apps from verified vendor accounts and block installation from unknown sources.
  • Apply mobile endpoint protections: use app integrity checks, runtime behavior monitoring, and allow‑listing for critical banking apps.
  • Network controls: monitor for unusual outbound connections from mobile devices to unknown domains/IPs and block command channels tied to identified infrastructure.
  • Telemetry & hunting: create SIEM rules to detect installation of unsigned APKs, suspicious SMS/OTP access, and background services spawned by banking‑style apps.
  • Containment: isolate affected devices, collect forensic images, and rotate credentials tied to impacted users.
  • User education: warn customers to verify publisher names, check permissions (SMS/device admin), and update apps only via official channels.

Our service offering

We provide actionable infrastructure mapping and operational support that includes:

  • Campaign attribution and infrastructure visualization
  • Tailored IOC packages and detection rules for mobile channels
  • Threat hunting and rapid response playbooks for financial services
  • Ongoing monitoring for infrastructure reuse and new variants

Protect your customers and preserve trust request a tailored assessment and mobile threat map.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]