A new Android malware campaign targeting Indian users through fake eChallanhas been reported by the Indian Computer Emergency Response Team, CERT-In. According to the agency, multiple reports indicate a coordinated effort by cybercriminals to steal sensitive financial and personal data through deceptive mobile apps and phishing techniques.
See also: Google adds “24-hour wait” for sideloading Android apps

The ongoing Android malware campaign revolves around fraudulent messages posing as official notifications eChallan or RTO Challan. Victims typically receive SMS notifications claiming that a traffic violation has been registered against their vehicle. These messages often include alarming language, such as legal threats or additional penalties, urging immediate action.
A common message reads: “Your vehicle challan has been generated. Download the receipt from the link below.” The link or attachment leads users to download malicious APK files with names like “RTO Challan.apk”, “RTO E Challan.apk” or even “MParivahan.apk”.
As CERT-In points out, these files act as entry points for a multi-layered malware infection. Once installed, the app appears in the app drawer, giving the illusion of legitimacy. However, it is only a distribution component. The actual malicious payload is deployed when users click on prompts like “Install Update.”
Once activated, the malware continues the eChallan theme but becomes invisible to the user, not appearing in the app list. At this stage, it aggressively requests sensitive permissions, including access to SMS messages, phone calls, and background activity.
See also: Perseus: New Android malware "reads" your notes

This access level allows attackers to maintain persistence on the device without detection. In some cases, the malware also requests permission to establish a VPN connection, enabling threat actors to monitor and intercept internet traffic.
The ultimate goal of this Android malware campaign is financial theft. Fake interfaces that resemble legitimate RTO Challan or banking pages are displayed to trick users into entering sensitive information such as card details and login credentials.
Last year, Cyble Research and Intelligence Labs (CRIL) reported a relative increase in browser-based phishing attacks exploiting the eChallan ecosystem. Unlike APK-based threats, this variant does not require users to install any apps, significantly lowering the barrier to compromise.
These phishing campaigns start similarly, with SMS messages targeting Indian vehicle owners. The messages contain deceptive URLs that mimic official eChallan portals. Once clicked, users are redirected to cloned websites that closely replicate government platforms, complete with official emblems and branding.
The research revealed that this Android malware campaign and related phishing operations are supported by a common backend infrastructure. Many domains impersonating eChallan, logistics services such as DTDC and Delhivery, and financial institutions were hosted on the same IP addresses.
See also: 6 new Android malware targets banking apps

Over 36 phishing domains linked to RTO Challan scams were detected on a single server. Another IP, 43[.]130[.]12[.]41, hosted additional domains that mimicked Parivahan services using misleading name patterns like “parizvaihen[.]icu”.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
