Description

A new phishing campaign has emerged, targeting SBI Bank customers through a fraudulent message circulating on WhatsApp. The message falsely claims that recipients have unclaimed SBI reward points worth Rs 9,980, which will expire unless they download a suspicious app called “SBI BANK REWARD App.” Distributed as an Android APK file named SBl REWARDZ POINT 1.apk, the app tricks users into depositing money into their accounts to claim the fake rewards. Cybersecurity experts warn that this is a sophisticated attempt to harvest sensitive user data. Analysis of the APK revealed that the app requests extensive permissions, including access to SMS, contacts, and call logs, which are commonly abused by malicious software. Hardcoded URLs linked to command-and-control servers, such as https://superherocloud.com and wss://socket.missyou9.in, were also found, indicating the app’s capability to exfiltrate user data. The app is designed to mimic the SBI login page, deceiving users into entering their credentials. These credentials are then sent to malicious servers. During dynamic testing with tools like Wireshark, the app exhibited persistent communication with remote servers, transmitting device details such as mobile IDs and SIM information. Additionally, it was found to exfiltrate user credentials, significantly increasing the risk of financial theft. This phishing campaign exploits urgency and trust to manipulate users. To mitigate risks, individuals are advised to avoid downloading apps from unverified sources, regularly monitor their bank statements for unauthorized transactions, and report suspicious activities to their financial institutions. Awareness and proactive measures are critical to preventing such cyber threats.