Security researchers reported coordinated phishing campaigns targeting customers of multiple Indian banks through SMS lures that redirected victims to spoofed banking and rewards pages or pushed malicious Android app downloads. Trend Micro said the activity targeted customers of seven banks and used several malware families, including Elibomi, FakeReward, AxBanker, IcRAT, and IcSpy, while Microsoft separately detailed a Rewards Plus cluster that impersonated mobile banking rewards programs to deliver an information-stealing remote access trojan. McAfee also documented related phishing malware aimed at Indian taxpayers, showing broader abuse of social-engineering themes tied to financial services and government processes.
The Android malware abused Accessibility services and other permissions to seize extensive control of infected devices, including capturing screenshots, unlocking phones, disabling protections, intercepting SMS messages and notifications, and exfiltrating personal, banking, and payment-card data to remote servers. Researchers said the operators relied on short-lived phishing domains, fake overlays, and reward-themed branding to evade detection and increase installs, creating a pathway for account takeover, credential theft, and fraudulent banking transactions affecting potentially millions of customers.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that AxBanker had been active since late August, targeting customers of a major Indian bank with reward-themed phishing pages. The malware stole SMS messages, personal information, and credit card data.
Trend Micro found a FakeReward phishing campaign in August targeting customers of three of the largest banks in India. The operation used bank-lookalike domains and fake reward or refund lures to steal personal, card, and message data.
Early in 2022, Trend Micro observed a new Elibomi variant with a package name ending in "iApp." This version added automation by abusing Android Accessibility permissions for clicking, permission granting, and screenshot capture.
Trend Micro said Elibomi activity continued in 2021 as part of phishing operations targeting customers of Indian banks. The malware family was used in SMS-driven lures leading victims to phishing sites or malicious Android apps.
Trend Micro reported that Elibomi first appeared in variants associated with "fake certificates" and "iMobile" phishing campaigns. These variants targeted Indian bank customers and remained active into the following year.
Trend Micro reported an uptick in phishing campaigns targeting customers of seven banks in India through SMS lures leading to phishing sites or malicious Android apps. The campaigns involved five malware families: Elibomi, FakeReward, AxBanker, IcRAT, and IcSpy.
Trend Micro later found a fourth Elibomi variant delivered from the same phishing site, with a package name ending in "iAssist." This variant added Firebase as an alternate command-and-control channel and used RDVerify for environment checks and evasion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcetrendmicro.com
Open sourcemicrosoft.com
Open sourcemcafee.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.