Cybercriminals Exploit Look-Alike mParivahan and e-Challan Apps in New Android Malware Campaign

Researchers at CYFIRMA have uncovered an advanced cybercrime operation, codenamed NexusRoute, that impersonates Indian government digital services, including the Ministry of Road Transport, mParivahan, and the e-Challan platforms.

The campaign employs phishing websites and fake Android applications to perpetrate mobile banking fraud, credential theft, and whole-device compromise.

Attackers host these malicious applications and phishing portals in GitHub repositories and on GitHub Pages, exploiting the trust users place in government-branded services.

Victims are drawn in through fake websites such as rtochallan[digits]. .shop or mparivahan1.github.io, which display logos of official state transport departments and prompt users to “verify” their challan by downloading an APK.

Once downloaded, the app installs a hidden Remote Access Trojan (RAT) that can control the infected device and steal sensitive data.

Technical Analysis Reveals Sophisticated Android RAT

CYFIRMA’s technical analysis shows that the NexusRoute malware is multi-staged and heavily obfuscated, featuring runtime code loading and native library execution via the Java Native Interface (JNI). These techniques hinder detection and make reverse engineering extremely difficult.

The malicious APK requests dangerous permissions, including READ_SMS, CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION, and SYSTEM_ALERT_WINDOW, enabling it to intercept OTPs, capture UPI PINs, record audio, and steal files.

Once installed, the malware registers BroadcastReceivers and foreground services to maintain persistence, surviving reboots and power-saving restrictions across major Android brands, including Xiaomi, Oppo, and Realme.

The RAT connects to a command-and-control (C2) server at 154.61.80.242:0999 using Socket.IO channels, allowing attackers to issue real-time instructions to capture screenshots, activate the microphone, or send SMS messages.

CYFIRMA identified exfiltration routines that gather SIM details, contact lists, GPS coordinates, and intercepted messages, all transmitted in encrypted JSON format.

Additionally, the malware employs a dynamic icon-swapping feature to disguise itself as legitimate Google apps such as “Translate” or “News,” thereby ensuring the infection remains undetected.

It even traps victims inside system settings loops to force permission approvals and fake “security update” installs.

mParivahan Android malware
mParivahan Android malware

OSINT analysis links the malware’s internal code and email artifacts to a broader Android obfuscation and surveillance development ecosystem known as Gymkhana Studio, suggesting ties to semi-commercial spyware production services.

CYFIRMA’s investigation identified more than 30 GitHub repositories hosting identical fake mParivahan APKs and phishing templates, indicating a highly automated, large-scale infrastructure.

The operation’s professional-grade tooling, persistence methods, and financial lures make it one of the most advanced Android threat campaigns seen in India.

Authorities, financial institutions, and citizens are urged to install apps only from trusted sources such as Google Play, avoid downloading APKs from unofficial websites, and report phishing portals that imitate government services to CERT-In or local cybercrime units.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories