A new wave of cyberattacks has emerged, targeting mobile users of a prominent Indian bank through a sophisticated malware campaign known as “FinStealer.”
This malware exploits the bank’s brand by distributing fraudulent mobile applications that mimic legitimate banking apps.
These malicious apps are disseminated through phishing links and social engineering tactics, deceiving users into divulging sensitive information such as login credentials, financial data, and personal details.
The attackers employ advanced evasion techniques, including encrypted communication with Command-and-Control (C2) servers, dynamic payload execution, and runtime behavior modification.

These methods allow the malware to bypass conventional security systems, posing a significant threat to both individuals and financial institutions.
How the Attack Works
The FinStealer campaign begins with phishing attempts that lure victims into downloading fake banking apps from unofficial sources.
Once installed, the malware requests permissions to access sensitive data, such as SMS messages and personal identifiers like Aadhaar and PAN card details.
According to the Cyfirma Report, it also intercepts one-time passwords (OTPs) and banking credentials, enabling unauthorized transactions.
The malware employs XOR encryption for string obfuscation and uses Telegram bots for C2 communication, ensuring stealthy data exfiltration.
Additionally, it exploits vulnerabilities in C2 servers using SQL injection techniques (e.g., CVE-2011-2688), allowing attackers to extract critical information like server passwords.

Implications and Risks
This campaign has exposed thousands of users to risks such as identity theft, unauthorized financial transactions, and the sale of stolen data on darknet forums.
The reliance on SMS-based OTPs for multi-factor authentication has been identified as a critical vulnerability.
Experts warn that OTP interception renders traditional authentication methods insufficient against modern threats.
The attackers’ use of Telegram bots and IP-based servers highlights their ability to maintain operational flexibility while evading detection.
Moreover, the stolen data is often stored in unsecured endpoints or cloud storage systems, further exacerbating the risk of unauthorized access.
To combat these threats, cybersecurity experts recommend:
- Downloading Apps Only from Trusted Sources: Users should avoid installing apps from unofficial platforms and rely solely on verified app stores like Google Play.
- Strengthening Authentication Mechanisms: Financial institutions are urged to adopt more robust multi-factor authentication methods beyond SMS-based OTPs.
- Proactive Monitoring: Organizations should implement advanced threat detection systems capable of identifying phishing campaigns and malware activity.
- User Education: Raising awareness about phishing tactics and safe online practices is crucial to mitigating risks.
The FinStealer attack underscores the growing sophistication of cybercriminals targeting India’s rapidly expanding digital banking ecosystem.
Both individuals and institutions must adopt comprehensive security measures to safeguard sensitive financial data against evolving threats.