Vietnamese Hacker Group Targets Indian Users with Fake E-Challan Scam via WhatsApp

Date:

Indian users are falling prey to a sophisticated scam involving fake e-challans delivered through WhatsApp, warns a recent report by CloudSEK, a leading cybersecurity firm. According to the report, scammers from a Vietnamese hacker group are orchestrating the scheme to steal personal data and money from unsuspecting victims.

The Modus Operandi

The scam begins with users receiving messages purportedly from Parivahan Sewa or Karnataka Police, issuing fake traffic violation fines. These messages contain links that, once clicked, prompt the download of a malicious Android application package (APK). Once installed, the malicious app requests extensive permissions, including access to contacts, SMS messages, and the ability to manipulate default messaging settings.

The Consequences

The malware, identified as part of the Wromba family, has already infected more than 4,400 devices nationwide. It operates by intercepting sensitive information like one-time passwords (OTPs), enabling hackers to compromise victims’ e-commerce accounts. Fraudulent transactions, primarily involving gift card purchases, have resulted in losses exceeding ₹ 16 lakhs.

Impact and Detection Challenges

Although users across India have been affected, Gujarat and Karnataka have reported the highest number of victims. The perpetrators, located in Báºïc Giang Province, Vietnam, use proxy IPs to evade detection, complicating law enforcement efforts.

Protecting Yourself

Vikas Kundu from CloudSEK emphasises the importance of proactive security measures:

  • Use Antivirus Software: Install reputable antivirus and anti-malware software on your devices.
  • Review App Permissions: Regularly audit and restrict app permissions to minimise exposure.
  • Download from Trusted Sources: Only download applications from official sources like the Google Play Store.
  • Keep Software Updated: Ensure your device’s operating system and apps are regularly updated to patch vulnerabilities.
  • Monitor SMS Activity: Employ tools that monitor and alert you to suspicious SMS activity.
  • Enable Account Alerts: Set up notifications for banking and other critical services to detect unauthorised access.
  • Promote Awareness: Educate yourself and others about the risks associated with unverified apps and phishing attempts.

By adopting these proactive measures, individuals can significantly mitigate the risk of falling victim to such sophisticated cyber threats. Stay vigilant and informed to safeguard your personal information from malicious actors.

Monika Shanmugam
Monika Shanmugam
Monika Shanmugamhttps://news.vakilsearch.com/
Hello! I am Monika Shanmugam. With 4 years of crafting engaging and informative content, I'm passionate about demystifying complex topics and weaving impactful narratives. My legal-writing journey began at Vakilsearch, where I spent the past year immersing myself in the intricacies of the legal landscape. This experience shaped my ability to translate legalese into digestible language, empowering individuals with the knowledge they need to navigate the legal system confidently.

Related Articles

More like this
Related

Germany Bans Oneplus Smartphones Over 5G Patent Disputes

OnePlus smartphones have been banned from sale in Germany...

DC and Marvel Lose Trademark Rights to ‘Superhero’

Marvel and DC Comics used to jointly own the...

Ravi Ahuja Appointed as CEO of Sony Pictures

Sony Pictures Entertainment (SPE) has announced a leadership change...

Old GST Dues Can Be Cleared Without Any...

New provision targets cases in which GST Dues were...