Search

Vietnamese Hackers Using ‘Maorrisbot’ to Target Indians in WhatsApp e-Challan Scam: CloudSEK

Scammers are reportedly sending fake eChallan messages over WhatsApp impersonating the Parivahan Sewa or Karnataka Police.

Advertisement
Highlights
  • A new malware called Maorrisbot is reportedly infecting Android devices
  • The malware is said to have affected more than 4,400 devices
  • Maorrisbot is capable of intercepting OTPs and other messages
Vietnamese Hackers Using ‘Maorrisbot’ to Target Indians in WhatsApp e-Challan Scam: CloudSEK

WhatsApp fake e-Challan scams have reportedly led to fraudulent transactions exceeding Rs. 16 lakh

Photo Credit: Reuters

WhatsApp e-Challan scams are targeting users India using Maorrisbot, a new form of technical malware, according to a cybersecurity firm. This is a relatively new type of scam that is reportedly backed by a large, organised effort. So far, the malware is said to be affecting only Android devices, and no impact has been seen on iOS or other Apple devices. The scam begins like a typical phishing scam, but once the malware is deployed on the victim's device, it acts as a trojan.

WhatsApp e-Challan Scams Using Maorrisbot to Target Indian Users

A new CloudSEK report details how the new malware dubbed Maorrisbot is used by hackers based in Vietnam. The firm states that a highly technical Android malware campaign is currently being uses to target users in India through fake traffic e-Challan messages disseminated via WhatsApp.

At the onset, the scammers impersonate the Parivahan Sewa or Karnataka Police and send messages to people asking them to pay their challan (traffic violation fine). These messages contain details of a fake e-Challan notice and a URL or an attached APK file.

The scammers trick the victim into clicking the link to pay the fine, and once that is done, the Maorrisbot is gets downloaded on the device. However, the report states that it is disguised as a legitimate application, which could mislead unwary users.

fake whatsapp echallan cloudsek whatsapp

The fraudulent message sent to victims by the hackers
Photo Credit: CloudSEK

 

After being installed, the malware begins requesting multiple permissions such as access to contacts, phone calls, SMS, and even to become the default messaging app. If the user allows these permissions, the malware begins intercepting OTPs and other sensitive messages. It can also use the data to log in to the victim's e-commerce accounts, purchase gift cards, and redeem them without leaving a trace.

The cybersecurity firm also found that the scammers use proxy IP and maintain a low transaction profile to avoid detection. The researchers believe the attackers are Vietnamese based on conversations and IP location — the purported hacker's IP address was traced to Bắc Giang Province in Vietnam.

CloudSEK claims that 4,451 devices are known to be compromised after installing the malware. The hackers have reportedly used 271 unique gift cards to steal more than Rs. 16 lakh from victims. Gujarat and Karnataka have been identified as the most affected region.

The security firm recommends Android users use well-known antivirus and anti-malware software, limit app permissions and regularly review them, and install apps only from trusted sources. Further, the firm also highlights monitoring suspicious SMS activity, regularly updating the device, and enabling alerts for banking and sensitive services.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing's Essential Space Feature Might Soon Require a Subcription
  2. Apple iPhone 16e Review: When You Just Need an iPhone
  3. Infinix Note 50X 5G With Dimensity 7300 Ultimate SoC Launched in India
  4. Samsung Galaxy S25 Edge Leaked Renders Suggest Three Titanium Colourways
  5. Qualcomm Could Launch 2nm Flagship Chipsets Next Year
  6. Airtel Launches IPTV Services With Bundled OTT Apps in India
  7. IPL 2025 Live Streaming for Free: How to Watch SRH vs LSG IPL Match Online?
  8. Vivo Y39 5G Launches in India With Snapdragon 4 Gen 2 Chipset
  9. New Research Suggests Dark Energy Is Evolving, Challenging Cosmology Models
  10. Why Google Is Reportedly Preparing to Develop Its Android OS in Private
  1. Samsung Handheld Gaming Device With Foldable Display Spotted in Design Patent
  2. Vivo Y39 5G With Snapdragon 4 Gen 2 SoC and 6,500mAh Battery Launched in India: Price, Specifications
  3. Google Play Store Blocks 17 Unregistered Crypto Exchanges in South Korea, Apple May Follow
  4. Alibaba Qwen 2.5 Omni AI Model With Real-Time Speech Generation Released
  5. Canon PowerShot V1 and EOS R50 V for Video Creators Launched: Price, Specifications
  6. iPhone 17 Series to Reportedly Get 8K Video Recording Support
  7. Infinix Note 50X 5G With MediaTek Dimensity 7300 Ultimate Chipset Launched in India: Price, Specifications
  8. PS Plus Monthly Games for April Announced: RoboCop: Rogue City, The Texas Chain Saw Massacre and Digimon Story
  9. Nothing Could Introduce Subscription Model for Essential Space Features on Nothing Phone 3a Series: Report
  10. OpenAI Close to Finalising $40 Billion SoftBank-Led Funding
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »