Trending Now
---Advertisement---

Keralam police warn of malicious APK scam via fake e-challan SMS

Summarize with AI

---Advertisement---

Thiruvananthapuram, Sep 26 The Keralam police have warned vehicle owners about a scam in which fraudsters use fake e-challan SMS messages to distribute malicious APK files and steal sensitive information.

According to a police statement, fraudsters send SMS messages from private mobile numbers containing seemingly genuine e-challan details and a link, making them appear to have been issued through an official government system.

On opening the link, users are directed to a fake website resembling the official Motor Vehicles Department e-challan portal and asked to enter their vehicle registration number.

The website then displays a dialogue box labelled “Internal Security Review”, showing the vehicle registration number, and prompts users to download an application to complete the verification. Selecting the “Yes” option downloads a malicious APK file, police said.

The Android Package Kit may seek various permissions that could allow fraudsters to gain control of the device and access or misuse sensitive information, it said.

Police urged people not to install APK files received through SMS, WhatsApp, Telegram or other messaging platforms in the name of e-challan, traffic fines, vehicle verification, KYC, refunds or RTO/MVD services.

People should check e-challan details only through the official MVD, Parivahan or e-challan websites and authorised government applications or portals, the statement said. Users should avoid opening links directly from SMS messages and instead access official websites by typing the address themselves or using verified government portals.

Instructions such as “Internal Review”, “Pending Verification” or “Install App to Clear Challan” appearing after a vehicle registration number is entered should be treated with suspicion, police said, adding that legitimate e-challan payment or verification services normally do not require users to download APK files from external sources.

Anyone who suspects a malicious APK has been installed should immediately disconnect the device from the internet and avoid using it for banking or other sensitive transactions, police advised.

They should remove suspicious applications where possible and seek assistance from the cyber police or a trusted technical professional, besides checking UPI and other payment services, linked bank accounts and recent transactions for any unauthorised activity.

If any suspicious transactions are detected, users should immediately contact their bank or payment service provider. People whose passwords or other credentials may have been compromised should change their banking, email and social media passwords using another secure device, police said.

People who receive such fraudulent messages or fall victim to the scam should report the matter to the cyber police through helpline 1930 or the cybercrime portal at the earliest, the statement said, adding that in cases involving financial fraud, prompt reporting can help authorities initiate measures to prevent or recover the funds.

(PTI News)

Join WhatsApp

Join Now
---Advertisement---

Leave a Comment