CYFIRMA Research

CYFIRMA Research- NexusRoute: Attempting to Disrupt an Indian Government Ministry

CYFIRMA

New Research Alert: NexusRoute Campaign Uncovered
 
 We’ve uncovered a large-scale Android malware and phishing operation impersonating Indian government services like mParivahan and e-Challan. Threat actors are abusing GitHub to host malicious APKs and fake payment portals, tricking users into sharing OTPs, UPI PINs, and financial details. The malware uses advanced techniques—dynamic loaders, native code, SMS hijacking, screen capture, and persistent background services—to monitor devices, steal data, and enable real-time fraud. This coordinated infrastructure shows that the campaign is highly professional and financially motivated, posing a serious national-scale cybersecurity threat.

Link to the Research Report: NexusRoute: Attempting to Disrupt an Indian Government Ministry - CYFIRMA

 #CyberSecurity #ThreatIntelligence #AndroidMalware #PhishingAlert #MalwareAnalysis #MobileSecurity #CyfirmaResearch #DigitalSafety #FraudPrevention #CyberThreat #InfoSec #CyberAwareness #CyberFraud #CyberDefense #CyberCrime #ExternalThreatLandscapeManagement #ETLM #CYFIRMA #CYFIRMAresearch

https://www.cyfirma.com/