A sophisticated malware campaign has emerged, targeting Android users in Indonesia and Vietnam with banking trojans disguised as legitimate government identity apps and payment services.

This malicious operation, active since approximately August 2024, uses advanced evasion techniques to distribute variants of the BankBot, while maintaining an extensive infrastructure with over 100 domains.
Threat actors demonstrate significant operational sophistication through the use of fake Google Play Store pages and government applications such as M-Pajak tax payment services and digital identity verification systems.
The campaign exploits users' trust in official government platforms, creating highly convincing fakes that trick victims into downloading malicious APK files containing banking trojans capable of stealing sensitive financial information and credentials.
See also: BMC vulnerabilities allow bypass of Signature Verification
DomainTools analysts identified the malware distribution pattern by monitoring suspicious website elements associated with fake Google Play Store pages.

Researchers uncovered a sophisticated distribution mechanism designed to bypass traditional network security controls and evade automated detection commonly used by cybersecurity frameworks.
Threat actors leverage WebSocket technology to bypass conventional security measures. Instead of providing direct download links that can be easily detected by security scanners, malicious websites use the Socket.IO library to create real-time, two-way communication channels between victims' browsers and command-and-control servers.
When users click the Android download button , the system initiates a WebSocket connection using the socket.emit('startDownload', …) command.
The server responds by transmitting the malicious APK file in chunks, rather than a complete file transfer. The browser collects these chunks via event listeners coded as socket.on('chunk', (chunk) => { chunks.push(chunk); }), while simultaneously receiving progress updates that maintain the illusion of a legitimate download.
See also: BRICKSTORM: Chinese hackers had access to American companies for a year
Upon completion, the system combines all the downloaded pieces in memory and assigns the MIME type application/vnd.android.package-archive to create a correct APK file structure.
The distribution mechanism then creates a temporary local URL and triggers an invisible download link, triggering the browser's standard file download interface.
This complex process effectively disguises malware distribution as encrypted WebSocket traffic, allowing malicious payloads to bypass network security systems configured to block direct APK downloads, while remaining invisible to static URL security scanners that scan websites for malicious links.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Banking trojans: Danger for users
The incident demonstrates two critical trends: First, attackers exploit trust in official services — with fake government apps and fake Play Stores — to convince victims to install “alternative” APKs. Second, the use of real-time socket transmissions (Socket.IO/WebSocket) allows payloads to be delivered in batches, bypassing static URL scanners and making network analysis more demanding.
See also: Chinese Hackers RedNovember Target Global Governments
Defensively, the message is clear: users should avoid third-party installations and check digital certificates and reviews on the official Play Store (to avoid banking trojans). Security organizations should add surveillance for non-standard WebSocket usage, analyze unusual data flows, and filter domains with indicators of malicious infrastructure.
Finally, the incident reminds us that the fight against mobile banking malware is not just technical — it also involves user education, strict management of the “install only from a trusted source” rule, and constant monitoring of infrastructures that use segmented or hidden file delivery routes.
The case demonstrates that cybercriminals move faster than defenses: the more complex the distribution methods, the more critical prevention, constant awareness, and collective vigilance of organizations and users become.
