Hero image showing NexusRoute Android malware impersonating Indian government apps to steal banking data and OTPs

Fake Indian Government Apps Used For Android Banking Login Theft

Category: Cybersecurity

A coordinated Android malware campaign called NexusRoute is targeting users by impersonating official Indian government apps like mParivahan and e-Challan. The operation relies on fake download pages, cloned branding, and malicious Android packages distributed through GitHub Pages. Once installed, the malware steals login credentials, banking data, and one-time passwords while maintaining deep, long-term access to infected devices. Security researchers at Cyfirma link the campaign to professional tooling and infrastructure rather than casual fraud.

Relevant Source (Verimatrix): How the Fake mParivahan App Hijacks Your Device
Verimatrix documents a fake mParivahan Android malware campaign that uses deceptive distribution and multi-stage techniques to steal sensitive user and financial information.

Quick Facts

  • Malware name: NexusRoute
  • Targets: Android users in India
  • Disguises itself as mParivahan and e-Challan apps
  • Distributed through phishing sites hosted on GitHub Pages
  • Steals SMS codes, UPI PINs, and banking credentials
  • Uses advanced persistence and surveillance techniques

NexusRoute Android Dropper Malware

NexusRoute is a multi-stage Android malware operation that pretends to be legitimate government transport and traffic apps. Victims are directed to convincing phishing pages that mirror official portals and instruct users to sideload the app by enabling unknown sources. After installation, the app acts as a dropper that quietly installs additional malicious components and begins harvesting sensitive data. Cyfirma analysts identified links to commercial Android obfuscation and surveillance ecosystems, pointing to a well funded and technically capable threat group.

  • Impersonates trusted government services
  • Uses fake payment and login screens
  • Installs hidden payloads after initial launch

NexusRoute is not a simple fake app. It is designed to blend in, survive removal attempts, and operate quietly in the background while collecting data at scale.

Relevant Source (CYFIRMA): NexusRoute: Attempting to Disrupt Indian Government
CYFIRMA reports NexusRoute as a multi-stage Android malware and phishing campaign that impersonates mParivahan and e-Challan, uses GitHub Pages for delivery, and steals credentials, OTPs, and payment data.

Accessibility Abuse Enables Takeover

This campaign goes beyond basic credential theft and enters the territory of full device compromise. By abusing Android permissions and accessibility services, the malware can read messages, approve actions, and monitor user behavior without ongoing interaction. The scale and polish of the operation suggest long-term data exploitation rather than one-time fraud. According to Cyfirma, the infrastructure and tooling resemble commercial surveillance platforms adapted for criminal use.

  • Reads SMS messages including one-time passwords
  • Captures UPI PINs and bank account details
  • Tracks location and device identifiers
  • Records call logs and contacts
  • Enables remote surveillance features

When malware gains accessibility access, it effectively bypasses Android’s user consent model. That creates a high-risk situation where financial loss and privacy invasion happen together.

Relevant Source (Google Security Blog): What’s New In Android Security And Privacy
Google outlines Android protections aimed at scams and fraud that commonly rely on risky permissions and social engineering, including accessibility-style takeovers tied to financial theft.

Clean Up A Compromised Android

Immediate action reduces damage and limits further exposure. Any device that installed unofficial mParivahan or e-Challan apps should be treated as compromised. Removing visible apps alone is not enough due to the malware’s persistence techniques. A cautious and methodical response matters.

  1. Uninstall suspicious apps and reboot the device
  2. Revoke accessibility, SMS, and device admin permissions
  3. Change banking, UPI, and account passwords from a clean device
  4. Contact banks to monitor or freeze affected accounts
  5. Perform a full factory reset if compromise is suspected

After cleanup, only install apps from the Google Play Store and verify the developer name carefully. Government services rarely require sideloading or intrusive permissions.

Relevant Source (Google Account Help): Remove Malware Or Unsafe Software
Google provides a step-by-step response for suspected Android malware, including removing untrusted apps, checking updates, and using Play Protect to reduce ongoing risk.

Professional Mobile Malware Ecosystem

NexusRoute reflects a broader shift in mobile malware toward professionalized operations that combine phishing, obfuscation, and long-term surveillance. Hosting payloads on trusted platforms like GitHub helps attackers bypass basic trust checks and reach large audiences quickly. Using native libraries, dynamic loading, and OEM-specific persistence shows deep knowledge of the Android ecosystem.

This type of campaign also highlights the limits of user awareness alone. Even cautious users can be misled by accurate branding and familiar service names. Platform level controls, stricter permission handling, and faster takedowns of abuse infrastructure are critical to reducing the impact of similar threats in the future.

Relevant Source (Microsoft Threat Intelligence): Malvertising campaign leads to info stealers
Microsoft documents attackers using GitHub as a trusted hosting platform in a large-scale malware delivery chain, which supports the point that modern campaigns blend deception with scalable infrastructure.

Avoid Fake Government Apps

Fake government apps remain one of the most effective social engineering tools on mobile devices. NexusRoute demonstrates how financial fraud and mobile surveillance are increasingly merged into a single attack model. Staying within official app stores, questioning unusual permission requests, and responding quickly to signs of compromise are the most reliable defenses for everyday users.

Relevant Source (Android Developers Blog): A New Layer Of Security For Android Devices
Google describes new Android protections aimed at reducing malware and scam installs, including safeguards around app installation and repeat bad actors.

FAQ

How did NexusRoute spread so widely?
Attackers used GitHub Pages to host fake download sites that looked legitimate and ranked well in searches.

Can antivirus apps detect this malware?
Some tools may flag parts of it, but the multi-stage loading and native code make detection inconsistent.

Why does accessibility access matter so much?
Accessibility allows the malware to approve permissions, read screens, and interact with apps silently.

Is uninstalling the app enough?
No. The malware hides additional components and survives standard removal attempts.

Are official mParivahan and e-Challan apps safe?
Yes. Apps downloaded directly from the Google Play Store under verified developers remain legitimate.

Malware Risks, Warning Signs, And How To Prevent It

How JENI Helps After Mobile Threats

JENI does not run on Android or mobile devices. Its role comes into play after a mobile malware incident, when users need a clean and stable computer to secure accounts, reset credentials, and review financial activity. Campaigns like NexusRoute force people to rely on their desktop or laptop to regain control safely.

What JENI Does Differently

  • Cleans and repairs Mac and Windows systems used for banking, passwords, and recovery
  • Removes hidden clutter and background issues that reduce system reliability
  • Operates fully local with no cloud access, tracking, or accounts

JENI supports recovery by ensuring the computer you use to respond to a mobile compromise is trustworthy and predictable. That matters because password resets, bank actions, and identity checks should never be done from an unstable or cluttered system. A clean desktop environment reduces follow-on risk after an Android infection. This complements platform security and good mobile habits without pretending to replace them.

Published on December 15, 2025 at 8:21 AM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.