
Cybersecurity firm CloudSEK has flagged a concerning trend in India where Vietnamese hackers are leveraging a new Android malware called Maorrisbot to perpetrate WhatsApp e-Challan scams. This sophisticated campaign involves impersonating authorities like Parivahan Sewa or Karnataka Police, enticing users to click on links or download APK files under the guise of paying traffic violation fines.
Upon installation, Maorrisbot disguises itself as a legitimate application while secretly deploying trojan-like functionalities on the victim’s device. It aggressively seeks permissions, including access to contacts, phone calls, SMS, and the ability to become the default messaging app. Once granted, the malware intercepts sensitive messages like OTPs, enabling attackers to exploit e-commerce accounts for unauthorized purchases, including gift cards.
CloudSEK has traced the origin of these attacks to Vietnam, pointing to IP addresses located in Bắc Giang Province. The firm estimates that 4,451 devices have already fallen victim to Maorrisbot, resulting in a financial loss exceeding Rs. 16 lakh from over 271 unique gift cards. Gujarat and Karnataka are notably the worst affected regions.
In response to this emerging threat, CloudSEK advises Android users in India to bolster their defenses with reputable antivirus and anti-malware software, strictly manage app permissions, and exercise caution when downloading applications. It also recommends vigilant monitoring of SMS activities, regular device updates, and enabling alerts for sensitive transactions.
As authorities and cybersecurity experts continue to combat these scams, vigilance and proactive security measures remain crucial to safeguarding against evolving cyber threats targeting unsuspecting users through sophisticated social engineering tactics.


















