Stopping the Steal: Mapping Infrastructure Behind Fake Indian Banking Apps on Android
Fraudsters are luring users with convincing fake banking apps on Google Play and third‑party stores to harvest login credentials, OTPs, and other sensitive data.

Fraudsters are luring users with convincing fake banking apps on Google Play and third‑party stores to harvest login credentials, OTPs, and other sensitive data. Our infrastructure mapping of this campaign reveals how attackers distribute, manage, and profit from these malicious apps, and gives defenders the edge to detect, contain, and block activity before customers are compromised.
Campaign summary

What it does: Fake banking apps impersonate legitimate bank clients to collect credentials and 2FA codes, often pairing a dropper/base payload with a second-stage payload that performs data collection and exfiltration.
How attackers operate:
Malicious apps delivered through official and third‑party stores using social engineering and fake reviews to appear legitimate.
Dropper/base payload installs a secondary/main payload that performs credential harvesting and persistence.
Command channels and distribution points used to push updates and harvest data from infected devices.
Rapid reuse of distribution assets across multiple imitations and regions to maximize yield.
Technical indicators Block and monitor immediately
Integrate the following hashes into your endpoint, mobile security, and network defenses. Add them to IOC feeds, EDR/MDM rule sets, and SIEM correlation rules.
| Indicator (SHA256) | Type | Remarks |
|---|---|---|
ee8e4415eb568a88c3db36098b7ae8019f4efe565eb8abd2e7ebba1b9fb1347d | SHA256 | Base payload / dropper |
131d6ee4484ff3a38425e4bc5d6bd361dfb818fe2f460bf64c2e9ac956cfb13d | SHA256 | Main payload (credential harvesting) |
Detection & mitigation guidance
- Block and quarantine files matching the above hashes at ingestion and execution points.
- Enforce app‑store hygiene: only permit apps from verified vendor accounts and block installation from unknown sources.
- Apply mobile endpoint protections: use app integrity checks, runtime behavior monitoring, and allow‑listing for critical banking apps.
- Network controls: monitor for unusual outbound connections from mobile devices to unknown domains/IPs and block command channels tied to identified infrastructure.
- Telemetry & hunting: create SIEM rules to detect installation of unsigned APKs, suspicious SMS/OTP access, and background services spawned by banking‑style apps.
- Containment: isolate affected devices, collect forensic images, and rotate credentials tied to impacted users.
- User education: warn customers to verify publisher names, check permissions (SMS/device admin), and update apps only via official channels.
Our service offering
We provide actionable infrastructure mapping and operational support that includes:
- Campaign attribution and infrastructure visualization
- Tailored IOC packages and detection rules for mobile channels
- Threat hunting and rapid response playbooks for financial services
- Ongoing monitoring for infrastructure reuse and new variants
Protect your customers and preserve trust request a tailored assessment and mobile threat map.



