How cybercriminals use social engineering and malicious APKs to scam users | Explained  

Share This Post

[ad_1]

The story so far: In mid-October, traveller Bhargavii Mani claimed that she lost close to ₹1 lakh while trying to book lounge access at the Bengaluru airport. The scam was allegedly executed after Mani was asked to download an APK (Android Package format) file that looked like a regular app, shared via a WhatsApp chat originating from an international number.

The malicious APK was able to function after she clicked on the link and granted screen mirroring access to a supposed customer care adviser during a video call.

When checking her credit card statement later, Mani noticed an unauthorised transaction of ₹87,125 to a PhonePe account. Additional transactions were also attempted but were denied due to the card reaching its spending limit.    

Mani also claimed her contacts were unable to reach her, and that a man was answering her calls. This could have been due to malicious call forwarding on her device.    

How do cybercriminals use Big Tech platforms? 

Mani said she was asked to download the malicious app from a fake website, which no longer exists. The URL presented to her was “Loungepass.in,” the link to which was shared through a WhatsApp business account. The phone registered to the account had an international number.

Mani claimed this fake website was one of the top results on Google, pointing to gaps in the verification process when big businesses are listed in search results.

Loungepass.com is a genuine website that allows users to pre-book airport lounge access at major airports. In Mani’s case, social engineering tactics were employed to lure her to the fake site; a method commonly used by threat actors.   

However, it is important to note that Apple’s iOS is designed to prevent apps from being downloaded or installed directly from a link that bypasses the official Apple App Store, which enforces strict security protocols. 

This is where the technical prowess of the scam comes into play.   

How did the malicious APK work? 

The only way to download an app on an iOS device is through the official Apple App Store. Apps in the store are verified by Apple and regularly checked for malicious code to ensure user security.  

However, users can download and test unreleased apps on their devices by enabling a hidden setting within iOS.  This feature allows users to test beta or unreleased versions of apps from developers.

“Apple’s Swift SDK also allows screen sharing (both in-app and in the background)”, explained cybersecurity researcher Vishesh Kochher.  

Scammers can use social engineering techniques to enable this setting and allow people to download malicious apps that appear to be legitimate.

In Mani’s case, once the malicious APK accessed her device, scammers likely enabled call forwarding.

For example, this can be done on Airtel’s network by dialling a code, followed by the phone number to which calls should be forwarded, Kochher explained.  

With call forwarding enabled, scammers can easily receive OTPs for transactions via phone banking.  

Kochher further says that an app could be used on iOS to initiate phone calls. With calls forwarded to the scammers’ number and outgoing calls controlled by the app, scammers could complete transactions without the user’s knowledge.  

“The technical sophistication of the app used in this scam appears similar to those used by online loan sharks, which access messages, photos, and stored information,” Kochher explained.  

Who was behind the scam? 

The website used to lure Mani into downloading the malicious app has been taken down.

A simple search for the registered domain name shows the website, hosted by Hostinger, was registered in Gujarat, India.  

However, further details about the individuals behind the website—such as their phone number, address, and organisation—were redacted from the registry. Investigators can request this information.  

How bad is the cybercrime situation in India? 

In 2023, Indian citizens lost ₹66.66 crore in 4,850 reported cases of online scams.

A report by the Indian Cybercrime Coordination Centre (I4C) revealed that digital financial frauds amounted to a staggering ₹1.25 lakh crore over the last three years.  

According to the National Cybercrime Reporting Portal (NCRP), at least ₹10,319 crore was reported lost by victims of digital financial fraud in 2023.  

Additionally, 5,252 suspect URLs have been reported so far.

The Parliamentary Standing Committee on Finance’s report on ‘Cybersecurity and Rising Incidents of Cyber/White Collar Crimes‘ noted that domestic fraud reported by Supervising Entities (SE) in FY23 totalled ₹2,537.35 crore.  

The use of sophisticated technical knowledge, coupled with social engineering techniques and a rise in data leaks, exacerbates the problem.  

India ranked fifth globally in the number of breached accounts in 2023, with 5.3 million leaked accounts. Scams enabled by social engineering and technical expertise are unlikely to disappear anytime soon.  

Users are advised to tread with caution when clicking on unverified links, downloading new apps, and scanning QR codes. They should periodically check for compromised passwords across all online accounts, and regularly review their card records for unknown transactions.

[ad_2]

Source link

Related Posts

Online Gaming Platform Shutdown Scams: A Warning Report

The world of online gaming is filled with exciting...

Dive Into New Challenges and Win Big

Embrace the Excitement of Overcoming Challenges and Achieving Great...

Portal Breakers Enter the Fractured Universe

The universe is far larger and stranger than most...

Adios, Windows: These alternatives make switching from Microsoft easy

If you can’t install Windows 11 on your...
- Advertisement -spot_img
Slot Gacor Slot777slot mahjongslot mahjongjudi bola onlinesabung ayam onlinejudi bola onlinelive casino onlineslot danaslot thailandsabung ayam onlinejudi bola onlinesitus live casino onlineslot mahjong waysbandar togel onlinejudi bolasabung ayam onlinejudi bolaSABUNG AYAM ONLINESABUNG AYAM ONLINEJUDI BOLA ONLINESABUNG AYAM ONLINEjudi bola onlineslot mahjong wayslive casino onlinejudi bola onlinejudi bola onlinesabung ayam onlinejudi bola onlinemahjong wayssabung ayam onlinesbobet88slot mahjongsabung ayam onlinesbobet mix parlayslot777judi bola onlinesabung ayam onlinesabung ayam onlinejudi bola onlinelive casino onlineslot mahjong waysjuara303juara303juara303juara303juara303juara303juara303juara303SV388Mix ParlayBLACKJACKSLOT777Sabung Ayam OnlineBandar Judi BolaAgen Sicbo Online
agen sabung ayamslot mahjong gacorsabung ayam onlinejudi bola onlinelive casino onlineslot mahjongsabung ayam onlinejudi bola onlinelive casino onlineslot mahjongslot mahjongsabung ayam onlinescatter hitamlive casino onlinemix parlaysabung ayam onlinelive casinomahjong waysmix parlaysabung ayam onlinelive casinomahjong waysmix parlaySBOBETSBOBETCASINO ONLINESBOBETSBOBET88SABUNG AYAM ONLINESBOBETagen judi bolalive casino onlinesabung ayam onlinejudi bola sbobetsabung ayam onlineSabung Ayam OnlineJudi Bola OnlineAgen Live Casino OnlineMahjong Ways 2Sabung Ayam OnlineJudi Bola OnlineAgen Live Casino OnlineMahjong Ways 2Sabung Ayam OnlineJudi Bola OnlineAgen Live Casino OnlineMahjong Ways 2slot gacorjudi bolamix parlayjudi bolasv388SABUNG AYAM ONLINELIVE CASINO ONLINEJUDI BOLAMAHJONG WAYSSLOT MAHJONGJUDI BOLA ONLINELIVE CASINO ONLINESABUNG AYAM ONLINE
SABUNG AYAM ONLINESABUNG AYAM ONLINEJUDI BOLA ONLINEJUDI BOLA ONLINESABUNG AYAM ONLINESABUNG AYAM ONLINESABUNG AYAM ONLINESABUNG AYAM ONLINEjudi bola onlinesabung ayam onlinelive casino onlinesitus toto 4djudi bola onlinejudi bola onlinesabung ayam onlinelive casino onlinejudi bola onlinemix parlaysbobet88sv388sbobet mix parlayws168sbobet88sv388sv388sbobet88sabung ayam onlinejudi bola onlinesabung ayam onlinesbobet mix parlaysabung ayam onlinejudi bola onlineslot gacorsabung ayam onlinejudi bola onlinelive casino onlineslot mahjong waysjuara303juara303juara303juara303juara303juara303juara303juara303juara303juara303juara303juara303juara303juara303juara303juara303SV388Mix ParlayLive Casino OnlineSitus Slot GacorSV388SBOBET WAPBlackjackPragmatic PlaySV388Judi Bola OnlineBlackjackKakek ZeusSV388Mix ParlayAgen BlackjackSlot Gacor Onlinesabung ayam onlinejudi bola onlinesabung ayam onlinejudi bola onlinejudi bola onlinejudi bola onlinejudi bola onlinesabung ayam onlinejudi bola onlineslot mahjong wayssabung ayam onlinejudi bolaslot mahjonglive casino onlinesabung ayam onlinejudi bola onlineslot mahjong gacorsitus toto togel 4Dsabung ayam onlinesitus toto togel 4Dsitus live casinojudi bola onlinesitus slot mahjongjudi bolasabung ayam onlinesabung ayam onlinemahjong wayssabung ayam onlinejudi bolasabung ayam onlinejudi bola
judi bola onlinejudi bola onlinejudi bola onlinejudi bola onlineJUDI BOLA ONLINESBOBET88JUDI BOLA ONLINEJUDI BOLA ONLINESV388Judi Bola OnlineBlackjackKakek ZeusSV388SBOBET WAPAgen BlackjackSlot Gacor Onlinejuara303juara303juara303juara303juara303juara303juara303juara303judi bola onlinejudi bola onlinejudi bola onlinesabung ayam onlinejudi bolasabung ayam onlinesabung ayam onlinejudi bola onlinesitus live casino onlineslot mahjong wayssabung ayam onlinesitus live casinojudi bola onlinedexel
Slot Mahjong Waysslot danaslot danaslot danasabung ayam onlinesabung ayam onlineJUDI BOLA ONLINESV388Mix ParlayAgen Casino OnlineSLOT777Sabung Ayam OnlineAgen Judi BolaLive Casino Onlinesabung ayam onlinesabung ayam onlinejudi bola onlineslot mahjong wayssabung ayam onlinejudi bola onlinesitus live casino onlineagen togel onlineSabung Ayam OnlineJudi Bola OnlineSlot MahjongBandar togelSabung Ayam OnlineJudi Bola Onlinejudi bola onlinejudi bola onlinesabung ayam onlinelive casino onlineJUDI BOLA ONLINESBOBET88JUDI BOLA ONLINEmix parlaymix parlaylive casinosabung ayam onlinemix parlayslot danaslot mahjongslot mahjongjudi bolaMAHJONG WAYS 2SABUNG AYAM ONLINELIVE CASINO ONLINESABUNG AYAM ONLINESBOBETLIVE CASINO ONLINESLOT MAHJONG WAYSSABUNG AYAM ONLINEMIX PARLAYSABUNG AYAM ONLINESABUNG AYAM ONLINEWALA MERONWALA MERONSITUS SABUNG AYAMSITUS SABUNG AYAMjudi bola terpercayaSabung Ayam Onlinemix parlaySabung Ayam OnlineZeus Slot GacorSitus Judi BolaSabung Ayam Onlinesitus sabung ayamSlot MahjongSV388SBOBET88live casino onlineslot mahjong gacorSV388SBOBET88live casino onlineslot mahjong gacorSabung Ayam OnlineJudi Bola OnlineCasino OnlineMahjong Ways 2Sabung Ayam OnlineJudi Bola OnlineLive Casino OnlineMahjong Ways 2judi bolacasino onlinesv388sabung ayam onlinejudi bola onlineagen live casino onlinemahjong waysLIVE CASINOJUDI BOLA ONLINESABUNG AYAM ONLINESITUS BOLASV388LIVE CASINO ONLINESLOT QRISSABUNG AYAM ONLINEMIX PARLAYMIX PARLAYJUDI BOLA ONLINESLOT MAHJONG
Mahjong Ways 2mahjong ways 2indojawa88daftar dan login wahanabetCapWorks Official ContactAynsley Official SitedexelHarifuku Clinic Official AccessNusa Islands Bali Official PackagesTrinidad and Tobago Pilots’ Association Official About PageNusa Islands Bali Official ContactCapworks Official SiteTech With Mike First Official SiteSahabat Tiopan Official SiteOcean E Soft Official SiteCang Vu Hai Phong Official SiteThe Flat Official SiteTop Dawg Tavern Official SiteDuhoc Interlink Official SiteRatiohead Official SiteMAN Surabaya E-Learning Official SiteShaker Group Official SiteTakaKawa Shoten Official SiteBrydan Solutions Official SiteConcursos Rodin Official SiteConmou Official SiteCareer Wings Official SiteMontero Espinosa Official SiteBDF Ventura Official SiteAkura Official SiteNamulanda Technical Institute Official Sitemenu home roasted coffeetosayama academy workshopjudi bola onlineContactez le Monaco Rugby Sevens - Club Professionnel à 7Virtual Eco Museum Official Event 2025DRT Seitai Official Contacta leading company in UWB technology development