Cyber Security News

Beware! Fake SBI Reward APK Attacking Users To Deliver Android Malware

Cybersecurity experts have uncovered a new Android malware campaign targeting unsuspecting users through a fake SBI Reward app.

Disguised as an official State Bank of India (SBI) rewards application, the malicious APK file is being distributed via WhatsApp messages.

The fake application is actively luring victims with promises of redeeming reward points worth ₹9,980.

Fake SBI Reward Application (Source – Malwr-Analysis)

This campaign highlights the growing sophistication of phishing attacks leveraging trusted brands to deceive users.

Cybersecurity professional, Anurag affirmed in his “Malwr-Analysis” blog that the attack begins with a WhatsApp message claiming that the recipient’s SBI reward points are about to expire.

The message includes a link to download an APK file named “SBI REWARDZ POINT 1.apk” (4.20 MB).

Once installed, the app requests excessive permissions, including access to SMS, contacts, call logs, and storage—permissions commonly abused by malware.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Technical Observations

APK Permissions

The malicious app’s AndroidManifest[.]xml reveals its intent to exploit device features:-

AndroidManifest.xml file (Source – Malwr-Analysis)
  • Permissions requested: Internet access, SMS reading/sending, call handling, and storage access.
  • Services and receivers: Components like SmsReceiver and BootBroadcastReceiver are designed to intercept SMS messages and execute tasks during system boot.

Network Traffic

Dynamic analysis using tools like Wireshark revealed that the app establishes connections with two command-and-control (C2) servers:

  1. wss://socket.missyou9[.]in
  2. https://superherocloud[.]com

These servers are used to exfiltrate sensitive data such as:-

  • Device manufacturer and model
  • Android version
  • SIM details
  • Mobile number

Additionally, the app periodically sends updates to these servers, exhibiting beaconing behavior.

Keylogging and Phishing

The fake app mimics legitimate SBI login pages to harvest user credentials, including:-

  • Username and password
  • Debit/credit card details (number, expiry date, CVV)
  • OTPs for financial transactions
Phishing screens mimicking legitimate SBI login pages (Source – Malwr-Analysis)

Captured credentials are transmitted to the server superherocloud[.]com, which was registered just two months ago.

Static analysis uncovered hardcoded URLs and references to financial APIs within the APK’s code. A suspicious name, “Kritika,” was also found in log statements, potentially identifying the developer or a debugging artifact.

API calls (Source – Malwr-Analysis)

The APK was flagged by 25 out of 67 antivirus engines on VirusTotal as a trojan. The domains associated with this campaign have been linked to similar malicious activities impersonating other banking apps.

This attack is a clear attempt to exploit user trust in SBI branding while creating urgency through fake reward expiration claims. Victims risk losing sensitive banking information, which could lead to unauthorized financial transactions.

As a recommendations, researcher urged to follow the guidelines mentioned below:-

  1. Avoid downloading APK files from unverified sources.
  2. Verify suspicious messages with official bank channels.
  3. Install apps only from trusted platforms like Google Play Store.
  4. Use antivirus software to detect malicious apps.
  5. Be cautious of messages creating urgency or offering rewards.

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago