FinanceLane
  • Funding
    • Equity Funding
    • Debt Funding
    • Crowdfunding
    • Real Estate Funding
  • Investing
    • Stocks
    • Bonds
    • Mutual Funds
    • Commodities
    • Forex
    • Private Equity
    • Real Estate
    • Crypto Investing
  • Lending
    • Personal Loan
    • Business Loan
    • Mortgage
    • Credit Card
    • Microfinance
    • Peer-to-Peer Lending
  • Insurance
    • Life Insurance
    • Health Insurance
    • Auto Insurance
    • Education Insurance
    • General Insurance
  • Banking
    • Individual Banking
    • Business Banking
    • Investment Banking
    • Neo Banking
    • Payments Bank
  • Wealth
    • Earning
    • Savings
    • Investments
    • Budgeting
    • Credit Management
    • Tax Planning
    • Retirement
  • Fintech
    • Payments
    • Digital Banks
    • Alternative Financing
    • Asset Management
    • Softwares
  • Startup
    • Startup Ecosystem
    • Merging & Acquisition
    • Equity Investing
    • Franchising
    • Business Offers
  • Crypto
    • Crypto Coins
    • Crypto Trading
    • Bitcoin
    • Blockchain
    • DAPP
    • Crypto Investing
  • Login
No Result
View All Result
FinanceLane
  • Home
  • Funding
  • Investing
  • Lending
  • Insurance
  • Banking
  • Wealth
  • Crypto
  • Newsletters
  • Feedback
Home News Feed Advisory

‘If you don’t click on this link and update KYC, bank account will be blocked’: New APK fraud scam could cost you lakhs, how to prevent

FinanceLaneby FinanceLane
August 3, 2024

In a recent public notice, Punjab and Sind Bank (PSB) has cautioned its customers about an ongoing scam in the bank’s name. The bank said that it is important for you to know about the scam to keep your money safe from the scamsters. This scam (APK file scam) starts with you receiving a fake message supposedly from the bank informing that your bank account will be blocked due to a KYC update. However, in reality, no such message has ever been sent by the bank, and neither is your KYC going to expire.

“They are asking customers to download APK files loaded with malware to steal account and personal information,” Punjab and Sind Bank said in the notice.

So how exactly does the scam happen? And what false narratives do the fraudsters create to lure you into following their call to action? Read below to know more about this and be alert.

How APK scam happens

The APK scam happens in three steps:
Step 1: Creating a false narrative to create panic
Step 2: Make you download a malicious APK file and install it

You Might Also Like:

Step 3: Perform fraudulent activities like installing a keylogger (a keylogger can see every keystroke you click on the mobile keyboard), launch a ransomware attack, or access the clipboard.
Step 1: The false narrative
According to Kaushik Ray, Chief Operating Officer (COO), of Whizhack Technologies, scamsters first send an SMS that looks like an SMS being sent by a bank – the tone and language of such a scam SMSes are very similar to real bank messages. This SMS contains a false narrative informing you about the blocking of your bank account or UPI activities or others due to pending KYC updates, or other reasons. “These narratives play on users’ desires or fears, effectively bypassing rational judgement and exploiting gaps in digital literacy,” says Ray.

“The intention behind such narratives is to create panic and then get you to install malicious APK files on the mobile devices. These are social engineering tactics. APK scams often work due to a combination of social engineering and user misinformation. Cybercriminals typically use compelling narratives that create a sense of urgency or offer a unique benefit to persuade users to download the APK,” he further explains.

You Might Also Like:

For example: The scam SMS may say that if you don’t click on this link to download the APK file, your bank account will be frozen as its KYC status is pending or lapsed, etc.

Another possible narrative is the scam SMS may tell you that your reward points are going to expire, so download the file to redeem them otherwise the accumulated points will be lost.

Ray informs that sometimes the narrative may not be using fear instead it could use greed. “For example, they might advertise an APK as a way to access a popular feature not yet available for others or an app that provides free services that would usually require payment,” he says.

Most of the time these narratives work in the scamster’s favour because people are inherently engineered to fear about the safety of their assets which in this case is money kept at the bank. Just imagine if someone impersonating a bank officer informs you that all the money you keep at the bank is going to be frozen for an undefined period if you don’t do this immediately. One of the first things that will play in your mind is how are you going to pay the school fees of your children, how to buy vegetables for tonight’s dinner, and how to even do a DTH or mobile recharge. A bank account powers our daily life in unimaginable ways and freezing it would mean getting cut off from life’s activities.

Step 2: Installing the malicious APK file

Once the scamsters manage to convince you with their narratives, they make you install the malicious APK files. “Post installation, the hacker receives a connection on his hacking device, thus granting access and control of the infected mobile device with the hacker to facilitate malicious actions,” says Ray.

Step 3: Launching the cyber scam attack

Ray informs that once the hacker gets control of the device, he/she may execute multiple attacks which may include a ransomware attack. If you are targeted for a ransomware attack, then your mobile device will get locked up and the hacker will not release the lock until you pay up the demanded ransom. The hacker may also threaten to expose private and confidential documents, photos, and others on the Internet if you fail to give the ransom money.

Ray further says that some hackers may not use ransomware against you and may instead install keyloggers to know your net banking ID and password, UPI PIN, or others. “One of the common functionalities of malware from fraudulent APKs can include keyloggers and clipboard access. A keylogger records all keystrokes made on the device, which can capture everything from passwords to credit card numbers. Similarly, by accessing the clipboard, the malware can read any data that has been copied, such as passwords and account numbers. This data can then be used to breach online banking or UPI accounts, leading to financial theft or identity fraud,” he says.

Punjab and Sind Bank alert

Source: Punjab and Sind Bank website as of August 2, 2024

How to prevent APK scams

According to the public notice by Punjab and Sind Bank, here is what you should do:

  • Never download files received from strangers,
  • Never click on unknown links
  • Block and report suspicious contacts
  • Do not share personal information with anyone online.

According to Ray, the APK scam specifically targets Android devices because APK is a file format used by Android.

“iOS devices use a different format called IPA (iOS App Store Package), and they have a closed ecosystem that generally doesn’t allow installation of apps from third-party sources without jailbreaking the device. This doesn’t mean iOS devices are immune to similar scams; they just don’t use APK files. iOS users can still be targeted through other means like phishing or malicious profiles and apps installed through exploitation of enterprise certificates or sideloading techniques,” he says.

Source Link

Related Topics

Advisory

ITR filing 2025: Five changes in ITR forms of FY 2024-25 (AY 2025-26)

Advisory

Home loan rate 8% or below: 10 banks offering lower interest rate to borrowers; check latest EMI on 30 lakh home loan

Prev Next

You May Like

Advisory

ITR filing 2025: Five changes in ITR forms of FY 2024-25 (AY 2025-26)

Advisory

Home loan rate 8% or below: 10 banks offering lower interest rate to borrowers; check latest EMI on 30 lakh home loan

Advisory

5 tips if you want to book cheap flight tickets for your next trip

Advisory

Gold loan rules: 9 proposals made by RBI in the draft guidelines and how they may impact your borrowing

Advisory

DU Admission 2025: 11 documents you should keep handy to secure admission in Delhi University

Advisory

5 cheapest international travel destinations in 2025, per airfares, as per Skyscanner

Advisory

SBI cuts fixed deposit interest rates again by 20 bps: Check latest FD rates

Advisory

Are banks open or closed today, May 17, 2025? Check the Saturday bank holiday status

Financial News

Bitcoin

Bitcoin Miner CEOs Are Upbeat Ahead of the Halving, Expect M&A: Bernstein

CoinDesk
by CoinDesk
Advisory

Deletion of daughter’s name from family details of central government pensioner: Govt clarifies

FinanceLane
by FinanceLane
Advisory

ChatGPT for fake Aadhaar and PAN: The artificial intelligence tool can be misused to generate photorealistic fake IDs

FinanceLane
by FinanceLane
Blockchain News

Ethereum Milestone: Validator Count Hits 1 Million with $114 Billion Staked

Blockchain
by Blockchain
Blockchain News

HTX Collaborates with Fireblocks to Enhance Security with Off Exchange Integration

Blockchain
by Blockchain
Blockchain News

Bitfinex Pay Introduces New Features and Fixes in Latest Update

Blockchain
by Blockchain
Advisory

What is the purpose of stock market indices? Here’s how an investor can actually use an index

FinanceLane
by FinanceLane
Blockchain News

VanEck CEO Predicts SEC Rejection of Spot Ethereum ETF Application in May

Blockchain
by Blockchain
Advisory

Bad experiences drive F&O retail investors to mutual funds: Sundeep Sikka ED & CEO, Nippon Life India AMC

FinanceLane
by FinanceLane
Advisory

​Ram Mandir inauguration: You can save tax by donating money to Ayodhya Ram Mandir; here’s how

FinanceLane
by FinanceLane
Blockchain News

Council of Europe Adopts Groundbreaking AI Guidelines for Journalism

Blockchain
by Blockchain
Blockchain News

Together AI Expands Capabilities with Acquisition of Refuel.ai

Blockchain
by Blockchain
Load More
FinanceLane.com
  • Disclaimer
  • Privacy Policy
  • Terms of use
  • Subscribe
  • Contact

Subscribe to get the latest updates

Follow us on

© 2022 FinanceLane.com. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Home
  • Funding
    • Equity Funding
    • Debt Funding
    • Real Estate Funding
    • Crowdfunding
  • Investing
    • Stocks
    • Bonds
    • Mutual Funds
    • Private Equity
    • Merging & Acquisition
    • Real Estate
  • Lending
    • Personal Loan
    • Business Loan
    • Credit Card
    • Microfinance
    • Peer-to-Peer Lending
  • Insurance
    • Life Insurance
    • Auto Insurance
    • Education Insurance
    • Health Insurance
  • Banking
    • Business Banking
    • Payments Bank
    • Investment Banking
    • Individual Banking
  • Wealth
    • Earning
    • Savings
    • Investments
    • Budgeting
    • Credit Management
    • Tax Planning
    • Retirement
  • Fintech
    • Alternative Financing
    • Payments
    • Asset Management
    • Digital Banks
    • Softwares
  • Fintech
    • Alternative Financing
    • Asset Management
    • Digital Banks
    • Softwares
    • Payments
  • Crypto
    • Crypto Investing
    • Crypto Trading
    • Crypto Coins
    • Bitcoin
    • Blockchain
    • DAPP
  • Subscribe
  • Contact
  • Login

© 2022 FinanceLane - Terms and Conditions | Disclaimer | Privacy Policy

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.