HomeSecurityNexusRoute: New malware campaign targets Android users

NexusRoute: New malware campaign targets Android users

A particularly sophisticated and alarming malware, dubbed NexusRoute, is in full swing, targeting primarily Android users in India by impersonating official government services. The operation is not limited to simple fraud, but combines phishing techniques, financial fraud, and full-scale mobile device surveillance, revealing an organized and professionally structured cybercrime ecosystem.

NexusRoute

Fake government applications as a Trojan horse

At the core of the campaign are fake versions of the popular government apps mParivahan and e-Challan, which are widely used in India for transportation and toll services. Fraudsters are exploiting citizens’ trust in government digital servicesby distributing apps that appear to be perfectly legitimate, but are in fact designed to steal credentials and financial data.

The attack is based on a multi-layered deception mechanism, which starts with fake download websites and ends with complete control of the victim's device.

GitHub as a malware distribution platform

One of the most worrying aspects of the case is the fact that the campaign is leveraging GitHub as a key distribution hub. Hundreds of fake repositories host malicious Android packages, giving the operation an appearance of legitimacy and making it difficult to immediately detect.

See also: Man jailed for giving “malware lessons” to hackers

Users are directed to GitHub pages that mimic official government portals, with authentic logos, colors, and terminology. There, they are asked to enable the installation of applications from “unknown sources,” a crucial step that paves the way for infection.

From simple installation to full device control

The initial malicious file acts as a dropper, requesting permissions that no genuine government application would require. These include reading SMS, accessing accessibility services, creating overlay windows, and full file system access.

NexusRoute: New malware campaign targets Android users

Once permissions are granted, NexusRoute gains almost complete control of the device, allowing interception of OTP messages, financial details, and personal data.

Multi-layered infection and concealment techniques

Cyfirma 's analysis revealed that the malware uses a multi-layered loading mechanism , designed to bypass detection systems and make reverse engineering difficult. Through the Java Native Interface , a native library called npdcc is loaded , transferring critical malicious logic into compiled code.

See also: Gentlemen ransomware compromises corporate networks to intercept and encrypt sensitive data

At the same time, DexClassLoader to dynamically load additional packages, allowing attackers to upgrade the malicious payload without a new installation by the user.

Persistence and psychological deception of users

Persistence is a key advantage of the campaign. NexusRoute is automatically activated upon device startup, masquerading as a security or backup and exploiting auto-start mechanisms specific to manufacturers such as Xiaomi and OPPO.

Particularly insidious is the use of fake notifications that mimic Google Play updates. Through these, users are convinced to approve additional permissions, which are then automatically activated through the accessibility service, without any further consent.

Data theft and complete monitoring

The stolen data is sent to command and control servers via Socket.IO. There, device identifiers, bank account details, UPI PINs, and SMS with one-time codes are collected. With this material, the perpetrators perform unauthorized transactions or sell the information to criminal networks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Phantom Stealer: Phishing attack with ISO images targets Russia

NexusRoute: New malware campaign targets Android users

Even more worryingly, publicly available evidence reveals dashboards with GPS tracking, microphone activation , and remote screen recording, confirming that NexusRoute goes beyond financial fraud and borders on full-blown digital espionage.

A warning message about mobile security

The NexusRoute case is a wake-up call for mobile security, especially in countries with mass adoption of digital government services. It shows how trust, combined with technical sophistication and professional infrastructure, can be turned into a large-scale weapon, with implications that go far beyond simply stealing money.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS