Government Warns Banking Users of Android Malware That Pretends to Help Generate Income Tax Refunds

CERT-In suggested that the Drinik malware evolved recently as a banking Trojan targeting Indian customers.

Advertisement
By Jagmeet Singh | Updated: 23 September 2021 17:37 IST
Highlights
  • CERT-In has issued an advisory to warn users about the malware
  • Indian bank customers are targeted for sensitive and financial data
  • Attackers pretend to help users generate tax refunds through an app

Customers of more than 27 Indian banks may have been targeted using the malware

Photo Credit: Unsplash/ Denny Müller

The government has warned Android users in India about a malware called Drinik to steal sensitive information by promising to generate income tax refunds. Customers of more than 27 Indian banks have already been targeted with the malware, the Indian Computer Emergency Response Team (CERT-In) wrote in an advisory released online. The nodal agency that deals with cybersecurity threats says that the attackers target victims by sending them a link to a phishing website that looks similar to the Income Tax Department portal. It asks users to download a malicious app that installs the Drinik malware.

The Drinik malware was reportedly used as a primitive SMS stealer back in 2016. CERT-In, though, suggested that it evolved recently as a banking Trojan, targeting Indian customers.

Advertisement

As per the details provided in the advisory by the CERT-In, victims receive an SMS message containing a link to the phishing site. It asks for some personal information and then downloads the app. The malicious Android app acts like a genuine version of the solution created by the Income Tax Department to help generate tax refunds. It requires users to grant permissions to access SMS messages, call logs, and contacts and shows a refund application form that asks for details including full name, PAN, Aadhaar number, address, and date of birth, according to the advisory.

In addition to personal details, the CERT-In says that the app asks for financial details such as account number, IFSC code, CIF number, and even debit card number, expiry date, CVV, and PIN.

Advertisement

The attackers claim that these details will be used to help generate tax refunds sent directly to the account of the user. However, in reality, the agency notes that once the user taps the ‘Transfer' button on the app, it shows an error and brings a fake update screen. This helps the attacker to run Trojan in the background that shares user details including their SMS messages and call logs.

By using the silently obtained details, the attackers are able to generate a bank-specific mobile banking screen to convince the user to enter their mobile banking credentials. These are later used for conducting financial frauds, the CERT-In said.

Advertisement

The agency advises banking customers to download apps directly from official app stores including Google Play. Users are also recommended to review the app details, number of downloads, user reviews, and comments before downloading an unknown app even from an official source. Additionally, the government body recommends users to not browse untrusted sites or follow untrusted links.


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Honor Earbuds 4 With Up to 46 Hours of Total Battery Life Debut Globally
  2. Vivo Confirms Upcoming Phone With Massive 10,200mAh Battery
  3. Lava Bold N1 5G Is Now Available in a New 6GB RAM, 128GB Storage Variant
  4. OnePlus Nord CE 6 Key Features Revealed Ahead of Launch in India
  1. Assassin's Creed Black Flag Resynced Pricing Leaked Ahead of Official Reveal
  2. Honor Earbuds 4 Launched Globally With Active Noise Cancellation, Up to 46 Hours of Total Battery Life
  3. Motorola Razr 70 Ultra Design, Colour Options Spotted in Leaked Renders and Promotional Image
  4. UK’s FCA Raids Multiple Sites Suspected of Illegal P2P Crypto Operations
  5. Honor Win H7, Win H9 Launched With Up to Intel Core 9 Ultra HX CPU: Price, Specifications
  6. WhatsApp Launches Prepaid Mobile Recharges for Users in India: How to Recharge Your Mobile Number
  7. Samsung Details Switchable 2D/3D Display Technology That Could Come to Future Galaxy Phones
  8. Crimson Desert Gets Difficulty Settings, Graphical Upgrades and Inventory Improvements in Latest Patch
  9. Spider-Noir OTT Release Date: When and Where to Watch Nicolas Cage Starrer
  10. Alpha: Men Love Vengeance OTT Release, Cast, Plot & Where to Watch on Amazon Prime Video
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.