Vietnamese Hackers Using ‘Maorrisbot’ to Target Indians in WhatsApp e-Challan Scam: CloudSEK

Scammers are reportedly sending fake eChallan messages over WhatsApp impersonating the Parivahan Sewa or Karnataka Police.

Advertisement
Written by Akash Dutta, Edited by David Delima | Updated: 17 July 2024 19:35 IST
Highlights
  • A new malware called Maorrisbot is reportedly infecting Android devices
  • The malware is said to have affected more than 4,400 devices
  • Maorrisbot is capable of intercepting OTPs and other messages

WhatsApp fake e-Challan scams have reportedly led to fraudulent transactions exceeding Rs. 16 lakh

Photo Credit: Reuters

WhatsApp e-Challan scams are targeting users India using Maorrisbot, a new form of technical malware, according to a cybersecurity firm. This is a relatively new type of scam that is reportedly backed by a large, organised effort. So far, the malware is said to be affecting only Android devices, and no impact has been seen on iOS or other Apple devices. The scam begins like a typical phishing scam, but once the malware is deployed on the victim's device, it acts as a trojan.

WhatsApp e-Challan Scams Using Maorrisbot to Target Indian Users

A new CloudSEK report details how the new malware dubbed Maorrisbot is used by hackers based in Vietnam. The firm states that a highly technical Android malware campaign is currently being uses to target users in India through fake traffic e-Challan messages disseminated via WhatsApp.

At the onset, the scammers impersonate the Parivahan Sewa or Karnataka Police and send messages to people asking them to pay their challan (traffic violation fine). These messages contain details of a fake e-Challan notice and a URL or an attached APK file.

Advertisement

The scammers trick the victim into clicking the link to pay the fine, and once that is done, the Maorrisbot is gets downloaded on the device. However, the report states that it is disguised as a legitimate application, which could mislead unwary users.

Advertisement

The fraudulent message sent to victims by the hackers
Photo Credit: CloudSEK

Advertisement

 

After being installed, the malware begins requesting multiple permissions such as access to contacts, phone calls, SMS, and even to become the default messaging app. If the user allows these permissions, the malware begins intercepting OTPs and other sensitive messages. It can also use the data to log in to the victim's e-commerce accounts, purchase gift cards, and redeem them without leaving a trace.

Advertisement

The cybersecurity firm also found that the scammers use proxy IP and maintain a low transaction profile to avoid detection. The researchers believe the attackers are Vietnamese based on conversations and IP location — the purported hacker's IP address was traced to Bắc Giang Province in Vietnam.

CloudSEK claims that 4,451 devices are known to be compromised after installing the malware. The hackers have reportedly used 271 unique gift cards to steal more than Rs. 16 lakh from victims. Gujarat and Karnataka have been identified as the most affected region.

The security firm recommends Android users use well-known antivirus and anti-malware software, limit app permissions and regularly review them, and install apps only from trusted sources. Further, the firm also highlights monitoring suspicious SMS activity, regularly updating the device, and enabling alerts for banking and sensitive services.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17e Launched in India With MagSafe, 48-Megapixel Camera: See Price
  2. Nothing Phone 4a Price in India, RAM and Storage Options Leaked Online
  3. iPad Air (2026) With M4 Chip Launched in India at This Price
  4. Ai+ Pulse 2 With 6,000mAh Battery Launched at This Price in India
  5. Xiaomi Watch 5, Xiaomi Tag Arrive Globally at These Prices
  6. The Motorola Razr Fold Just Made an Appearance on Geekbench Ahead of MWC
  7. Qualcomm Unveils FastConnect 8800, X105 5G Modem and Snapdragon Wear Elite
  1. Total Lunar Eclipse 2026: Where and How to See the Rare Blood Moon
  2. Poco X8 Series, Poco C85x 5G Teased on Flipkart, Could Launch in India in March
  3. iPad Air (2026) Launched in India With M4 Chip, Up to 13-Inch Display: Price, Specifications
  4. iPhone 17e Launched in India With MagSafe, Ceramic Shield 2 and A19 Chip: Price, Specifications
  5. MWC 2026: Tecno Camon 50 Series Launched as Firm Unveils Modular Concept Phone, Lamborghini Collaboration
  6. Samsung Galaxy S26 Ultra's Successor Tipped to Feature 200-Megapixel ISOCELL HPA Sensor With LOFIC
  7. Moto Buds 2 Plus Launched With Dynamic ANC, Sound by Bose Alongside Moto Buds 2 at MWC 2026
  8. MediaTek Set to Demonstrate 6G, 5G-Advanced, Edge AI Innovations at ‘AI For Life’ Showcase at MWC 2026
  9. MWC 2026: Lenovo Unveils New Yoga, IdeaPad Series Laptop Models Alongside Legion Tab (2026), Idea Tab Pro Gen 2
  10. With Love OTT Release Date: When and Where to Watch it Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.