Government Warns Banking Users of Android Malware That Pretends to Help Generate Income Tax Refunds

CERT-In suggested that the Drinik malware evolved recently as a banking Trojan targeting Indian customers.

Advertisement
By Jagmeet Singh | Updated: 23 September 2021 17:37 IST
Highlights
  • CERT-In has issued an advisory to warn users about the malware
  • Indian bank customers are targeted for sensitive and financial data
  • Attackers pretend to help users generate tax refunds through an app

Customers of more than 27 Indian banks may have been targeted using the malware

Photo Credit: Unsplash/ Denny Müller

The government has warned Android users in India about a malware called Drinik to steal sensitive information by promising to generate income tax refunds. Customers of more than 27 Indian banks have already been targeted with the malware, the Indian Computer Emergency Response Team (CERT-In) wrote in an advisory released online. The nodal agency that deals with cybersecurity threats says that the attackers target victims by sending them a link to a phishing website that looks similar to the Income Tax Department portal. It asks users to download a malicious app that installs the Drinik malware.

The Drinik malware was reportedly used as a primitive SMS stealer back in 2016. CERT-In, though, suggested that it evolved recently as a banking Trojan, targeting Indian customers.

Advertisement

As per the details provided in the advisory by the CERT-In, victims receive an SMS message containing a link to the phishing site. It asks for some personal information and then downloads the app. The malicious Android app acts like a genuine version of the solution created by the Income Tax Department to help generate tax refunds. It requires users to grant permissions to access SMS messages, call logs, and contacts and shows a refund application form that asks for details including full name, PAN, Aadhaar number, address, and date of birth, according to the advisory.

In addition to personal details, the CERT-In says that the app asks for financial details such as account number, IFSC code, CIF number, and even debit card number, expiry date, CVV, and PIN.

Advertisement

The attackers claim that these details will be used to help generate tax refunds sent directly to the account of the user. However, in reality, the agency notes that once the user taps the ‘Transfer' button on the app, it shows an error and brings a fake update screen. This helps the attacker to run Trojan in the background that shares user details including their SMS messages and call logs.

By using the silently obtained details, the attackers are able to generate a bank-specific mobile banking screen to convince the user to enter their mobile banking credentials. These are later used for conducting financial frauds, the CERT-In said.

Advertisement

The agency advises banking customers to download apps directly from official app stores including Google Play. Users are also recommended to review the app details, number of downloads, user reviews, and comments before downloading an unknown app even from an official source. Additionally, the government body recommends users to not browse untrusted sites or follow untrusted links.


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. HTX Delists USD1 Stablecoin, Asks WLFI to Reverse Freeze
  2. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  3. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  4. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  5. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  6. OnePlus Turbo 6X Series Will Launch in China on This Date
  7. Samsung Galaxy A27 Spotted in Leaked Mint Colourway, Might Launch Soon
  8. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  1. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  2. Redmi Turbo 5 Confirmed to Launch in India With Identical Dual Rear Camera Setup as Chinese Variant
  3. OnePlus Turbo 6X Series Launch Date Announced Along With Key Specifications, Features
  4. WWDC 2026: Tim Cook’s Final Apple Keynote Marks the End of an Era
  5. Infinix Smart 20 Launched in India With MediaTek Helio G81 Ultimate SoC, Slim 7.7mm Profile: Price, Features
  6. Infinix Hot 70 Pro India Launch Timeline Leaked; Could Feature Dimensity 7100 Chip, 6,000mAh Battery
  7. Bitcoin Rebounds Above $62,000 as Buyers Return at Lower Prices Despite ETF Outflow Concerns
  8. Samsung Galaxy S26 FE WPC Database Listing Reveals Design, Qi2 Wireless Charging Support
  9. Apple's Foldable iPhone Seen in New Images of Dummy Units That Reveal Design
  10. Samsung Galaxy S27 Pro Leak Hints at Display Size, Tipped to Launch With 5,000mAh Battery
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.