A sophisticated Android banking trojan is actively circulating via WhatsApp, masquerading as a mandatory “Banking KYC” verification service.
This financially motivated malware uses deceptive social engineering to trick users into installing a malicious application, ultimately leading to severe device compromise.
By mimicking legitimate banking workflows, the threat actors successfully steal sensitive financial data, intercept SMS messages, and remotely hijack device communications.
Multi-Stage Infection and Evasion Tactics
The malware operates using a complex two-stage dropper architecture to remain undetected. The primary application acts as a stealthy loader, presenting victims with a fake “Update Required” prompt.
In the background, it extracts, decrypts, and installs a secondary payload using Android’s session-based PackageInstaller. To minimize suspicion and maintain persistence, the secondary malicious application intentionally hides its icon from the device’s app launcher.
Evasion is a central feature of this campaign. The malware embeds critical configuration details including its command-and-control (C2) endpoint, encryption keys, and agent identifiers within an obfuscated native library (libnative-lib.so).
This tactic severely limits visibility during static analysis and complicates reverse engineering efforts.
Furthermore, the malware establishes a local full-tunnel VPN service. By forcing all device traffic through this application-controlled network layer, attackers can monitor live communications, filter traffic, and potentially disrupt cloud-based security scans such as Google Play Protect.

To ensure uninterrupted operation, the Trojan forces a prompt requesting exemption from battery optimization policies, allowing it to run continuously in the background.
Remote operations rely heavily on Firebase Cloud Messaging. This integration allows attackers to issue real-time commands for SMS interception, bulk inbox extraction, remote call initiation, and USSD code execution, which can be used to alter call forwarding settings maliciously.

Phishing, Data Theft, and Threat Actor Links
Once the payload establishes control, the malware deploys an embedded Next.js WebView interface to execute its phishing campaign.
This frontend flawlessly mimics official banking KYC compliance screens, guiding victims through a multi-stage credential harvesting process.

Users are manipulated into submitting highly sensitive information, including their mobile numbers, ATM PINs, Aadhaar identification numbers, and full credit or debit card details.
The scale of this operation cyfirma, combined with its heavy focus on Indian banking credentials and identity data, strongly aligns with known organized mobile fraud ecosystems operating within India.
The campaign’s evolution from simple string obfuscation to native code concealment highlights the growing technical sophistication of these regional threat actors, emphasizing the critical need for strict app installation controls and heightened user skepticism toward unsolicited compliance alerts on messaging platforms.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.