The invitation is an APK
How wedding cards and traffic challans became India's most personal malware, and what an investigation has to capture.
Manuj Kumar Pandey28 Sep 20267 min read
The file arrives from an uncle's number, in the family group, a week before a wedding everyone knows about. It ends in .apk, not .pdf. Nobody checks.
Through 2025 and into 2026, the most effective mobile malware in India has not needed an exploit. It needs a reason to be opened. Wedding invitations, pending RTO challans, PM-Kisan instalments, courier delivery slips and KYC reminders have all been used as the wrapper, and police cyber cells from Himachal Pradesh to Telangana have issued warnings about the same pattern.
Why it works
Three things make this campaign different from the lottery SMS it replaced. It arrives from a contact the victim already trusts, because the previous victim's phone forwards it. It borrows an event the victim is expecting, so the name of the file is plausible. And it carries a deadline: a fine to be paid today, a ceremony next week, a parcel waiting at the depot.
None of this is technically sophisticated. It is social engineering fitted to how Indian families and small businesses actually use WhatsApp: large groups, forwarded media, and phones shared between work and home.
What the file does once installed
Published analysis of the challan variant describes a two-stage dropper: the first app is a thin installer that fetches the real payload, hides its own icon and asks for permissions one plausible prompt at a time. Other variants seen in the same period behave the same way.
OTP interception by reading SMS and notifications before the owner sees them.Identity harvesting of Aadhaar, PAN, SIM and contact data from the device.Accessibility abuse that lets the operator tap buttons inside a banking or UPI app.Battery-optimisation exemption so the service survives restarts and cleaners.A private VPN tunnel that hides command-and-control traffic from on-device security tools.Self-propagation through the victim's own WhatsApp, which is also why many accounts end up banned.
The victim's bank sends the OTP. The victim never sees it. That is the whole attack.
What an investigation should preserve
These cases are usually reported after money has moved, often hours later. By then the victim has uninstalled the app, factory-reset the phone, or both. The evidence that makes the case prosecutable is on the device and in the chat, and it is fragile.
The original message with sender number, group name and timestamp, before it is deleted.The APK itself hashed on collection, so the sample can be tied to other complaints.Installed package list and permissions captured before uninstalling anything.SMS and notification history covering the window in which OTPs were intercepted.Bank and UPI transaction references requested early, while the money trail is still warm.The infrastructure domains and servers the sample talks to, which link one victim to a campaign.
Linking samples matters more than it looks. The same signing certificate or command server appearing across complaints turns a dozen small frauds into one organised operation, and changes how an agency and a court treat the case.
The legal grounds
Under the Information Technology Act, 2000, installing the payload and taking data is covered by Section 43 read with Section 66; using the victim's identity or OTP falls under Section 66C; and the impersonation that makes the lure work is cheating by personation using a computer resource under Section 66D. The Bharatiya Nyaya Sanhita, 2023 adds cheating and cheating by personation. Electronic evidence now travels under the Bharatiya Sakshya Adhiniyam, which is why hashing and a documented chain of custody from the first collection are worth the trouble.
Individuals should report on the national cybercrime helpline, 1930, or at cybercrime.gov.in, as early as possible; speed is what makes a freeze on the receiving accounts possible. Organisations have a separate clock: CERT-In directions require specified cyber incidents to be reported within six hours of being noticed, and a compromised employee phone with access to company systems can qualify.
What an organisation should change
Block sideloading on every managed device, with no exceptions for senior staff.Vet the apps that are allowed including vendor and partner apps, before they reach employees.Treat a suspect phone as an incident and examine it before anyone wipes it.Tell staff plainly that no government department sends a challan, subsidy or KYC update as an APK.Rehearse the first hour who isolates the device, who calls the bank, who files the report.
The campaign will keep changing its wrapper: electricity bills, exam results, festival offers. The underlying behaviour does not change, and that is what detection and investigation should be built around.
Sources
CYFIRMA: RTO Challan fraud: a technical report on APK-based financial and identity theft ↗The420.in: RTO e-challan scam: fake APK files used to empty bank accounts ↗Deccan Herald: Himachal Pradesh police alert on wedding-invitation APKs ↗Tribune: Himachal cyber cell warning on challan APK links ↗