Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The application presents itself as a trusted banking KYC service, exploiting a routine process that millions of Indian bank users are already familiar with.
It registers with Firebase Cloud Messaging, establishing a persistent push-based remote command channel for the attacker.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking malware delivered via WhatsApp that impersonates a banking KYC verification app to steal financial and identity data. It operates as a two-stage dropper, decrypting and installing a secondary payload that intercepts OTPs, forwards SMS, places calls, hides its launcher icon, registers for Firebase Cloud Messaging-based remote control, and uses a full-tunnel VPN to route traffic through attacker-controlled infrastructure.
Android financial-theft malware distributed through WhatsApp, primarily targeting banking users in India. It impersonates a banking KYC application and uses a fake update workflow to deploy a concealed secondary APK, com.am5maw3.android. The payload intercepts and forwards SMS messages, extracts the SMS inbox, sends messages, initiates calls, and executes USSD commands, including call-forwarding operations. Staged WebView phishing pages collect mobile numbers, ATM PINs, Aadhaar numbers, dates of birth, and payment-card details. Firebase Cloud Messaging delivers remote commands, while locally encrypted credentials and event logs are exfiltrated to jsonapi.biz. Native-library configuration concealment, launcher suppression, battery-optimization exemptions, and an application-controlled VPN support stealth and sustained operation. The report hypothesizes links to earlier RTO e-Challan fraud activity but does not identify a named threat actor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.