Authorities are sounding the alarm as more users fall victim to severe financial losses after downloading malicious Android installation files from unofficial sources. Criminals are using a combination of social engineering and advanced banking malware to exploit unsuspecting individuals.
Significant Losses from Compromised Apps
Recent reports reveal numerous cases where individuals have been defrauded of substantial amounts. For example, a forestry official lost nearly one million rupees after executing a manipulated file on his smartphone. In another incident, a man who installed an app to book a doctor’s appointment found around 98,000 rupees withdrawn from his account shortly thereafter.
The scam typically follows a similar pattern: perpetrators contact their victims via messaging services or phishing emails, using deception to persuade them to manually install an APK file. Since these files are not vetted by official platforms like the Google Play Store, they can gain extensive permissions on the devices.
Banking Trojan with Remote Control Capabilities
Security researchers are currently warning about a new iteration of the banking Trojan known as “Hook v3.” This malware leverages the Android Debug Bridge (ADB) to provide complete remote control over the device. Analysis indicates that the malware features more than 100 different commands.
Banking apps, messaging platforms, and sensitive credentials make smartphones prime targets for cybercriminals. Protecting your Android device against hackers and data theft can be done quickly. For detailed advice, check out our free PDF guide: Discover 5 actionable protection measures.
With the capabilities of this malware, attackers can bypass lock screens, intercept SMS messages containing one-time passwords, or overlay fake screens over banking apps to capture login details. Additionally, the software can act as ransomware, rendering the device unusable for its owner. The spread of this malware is not limited to targeted messages but also occurs through developer platforms like GitHub.
Quishing and Smishing on the Rise
The increase in APK fraud cases is part of a broader escalation in threat levels. Analysts noted a significant surge in attacks via QR codes (quishing) and SMS (smishing) in the first half of 2026, with growth rates reportedly in the triple-digit percentage range.
Simultaneously, India’s market regulator, SEBI, has warned companies about the “boss scam,” wherein criminals impersonate executives using AI-generated voice cloning or manipulated messaging profiles. They pressure employees in finance departments into urgent transfers or urge them to download harmful software. One affected company in Mumbai lost a double-digit million sum over two weeks due to this scheme.
Running an outdated operating system is often the most significant vulnerability, akin to leaving the front door open for Trojans and malware. A free report is available that describes how you can close security gaps and protect your smartphone permanently by implementing the right updates. Download the free update guide now.
How to Protect Yourself
Experts strongly advise against permitting app installations from unknown sources or via forwarded links. Financial transactions or installation requests received through messaging services should always be verified via an independent channel, such as a direct call to the concerned person or institution.
Regular security updates are essential for keeping your mobile devices up-to-date. Additionally, be vigilant for suspicious activities within the accessibility settings, as malware often exploits these features.

