New Malware Targets Indian Bank Users to Steal Aadhaar, PAN, ATM & Credit Card PINs

A newly discovered malware campaign, “FatBoyPanel,” is targeting Indian bank users, stealing Aadhaar numbers, PAN details, ATM PINs, and credit card information. Researchers have identified nearly 900 malware samples designed to trick users into revealing sensitive data.
How the Attack Works:
- The malware spreads via WhatsApp as APK files disguised as official banking or government apps.
- Once installed, it mimics legitimate banking apps to steal user credentials.

- It intercepts SMS messages, including one-time passwords (OTPs), to facilitate unauthorized transactions.
- The malware has three key variants:
- SMS Forwarding: Sends stolen SMS data to an attacker-controlled phone number.
- Firebase-Exfiltration: Sends data to a Firebase server acting as a command-and-control center.
- Hybrid Variant: Combines both techniques for maximum data theft.
Major Impacts:
- 50,000+ users affected, with stolen bank details, card credentials, and government-issued IDs.
- Over 1,000 attacker-controlled phone numbers identified in the operation.
- The stolen data enables fraudulent banking transactions and identity theft.
How to Stay Protected:
- Download apps only from trusted sources (Google Play Store, Apple App Store).
- Enable Multi-Factor Authentication (MFA) (OTP, biometric authentication).
- Avoid clicking on unknown links or downloading APK files from WhatsApp or emails.
- Monitor bank statements regularly for suspicious transactions.
- Use a trusted mobile security solution like NPAV Mobile Security to detect and block malware threats.
Comment(s)
Categories
- Other (42)
- Ransomware (142)
- Events and News (27)
- Features (45)
- Security (466)
- Tips (79)
- Google (23)
- Achievements (11)
- Products (34)
- Activation (7)
- Dealers (1)
- Bank Phishing (44)
- Malware Alerts (212)
- Cyber Attack (259)
- Data Backup (11)
- Data Breach (97)
- Phishing (154)
- Securty Tips (1)
- Browser Hijack (18)
- Adware (15)
- Email And Password (68)
- Android Security (70)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (8)
- vulnerability (56)
- Hacker (31)
- Spyware (9)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (4)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (7)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (11)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (10)
- Impersonation phishing (1)
- DDoS (5)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
Recent Posts
Archive
Tags
cyber attack
phishing
data breach
phishing attacks
cyber threats
ransomware
phishing attack
ransomeware
malware
android malware
cyber security
data theft
phishingattack
cyberthreats
financial security
data stealing
cybercrime
network security
ddos attack
data security
critical vulnerability
cyber fraud
trojan
net protector total security
data protection
cert-in
financial fraud
phishing email
microsoft
lockbit
cybercriminals
cyber crime
ddos
phishing scam
cyber threat
india
twitter
android
ransomware attacks
cryptojacking
winrar
malicious apps
pakistan-backed hacker
android apps
email phishing
play store
server security
databreach
clop
ransomware attack