Tuesday, April 20, 2021
Home Business finance Report: 5 Indian Banks Targeted Into Phishing Scams

Report: 5 Indian Banks Targeted Into Phishing Scams

The targeted banks in the campaign include the State Bank of India, ICICI, HDFC, Axis Bank, and Punjab National Bank

Cybercriminals are trying to lure Indian users into phishing scams revealing important personal information with a new report on Monday warning that suspicious messages asking users to submit an application for the disbursement of income tax refund have been doing the rounds, with a link that directs users to a webpage looking like the income tax e-filing web page.

The targeted banks in the campaign include the State Bank of India, ICICI, HDFC, Axis Bank, and Punjab National Bank, revealed an investigation by New Delhi-based think tank CyberPeace Foundation along with cybersecurity services firmAutobot Infosec. The suspicious links originate from the US and France, said the report, adding that the campaign is collecting personal as well as banking information from the user, and getting into this type of trap could cause a massive financial loss for the users.

Follow NewsGram on Facebook to stay updated.

The shared link with the SMS has no domain name and is not linked with the Indian government. All IP addresses associated with the campaign belong to some third-party dedicated cloud hosting providers, said the report. The whole campaign uses plain HTTP protocol instead of secure HTTPS. This means anyone on the network or internet can intercept the traffic and get the confidential information in plain text to misuse against the victim.

It asks users to download an application from a third-party source instead of Google Playstore. The application asks to provide administrator rights and unnecessary access permissions of the device. On opening the link http://204.44.124[.]160/ITR, users are redirected to a landing page that is mostly similar to the government income tax e-filing website.

phishing scams

The suspicious links originate from the US and France. Pixabay

On clicking the green ‘Proceed to the verification steps’ button, users are asked to submit personal information such as full name, PAN, Aadhar number, address, Pincode, date of birth, mobile number, email address, gender, marital status, and banking information like account number, IFSC code, card number, expiry date, CVV/CVC and card PIN.

Additionally, the bank name is automatically detected from the IFSC code entered in the form. After submission of data, users are redirected to a page where they are asked to confirm the entered data. Clicking on the green ‘confirm’ button directs users to a fake banking login page almost similar to the official one. It asks for the username and password for online banking.

ALSO READ: Scams That Are Taking Place In The Economic World Beginners Must Be Aware

After these details are entered, for the next step, users are asked to enter a Hint question, Answer, Profile password, and CIF number. Once submitted, a mobile verification section with instructions provided to download an android application (.apk file) appears, to complete the ITR verification. Here, users are deliberately instructed to grant all device permissions to the particular application for phishing scams, the investigation revealed.

The application, called Certificate.apk, starts downloading upon clicking the green ‘Download’ link. The overall layout and functionalities of the web page used in the campaign are similar to the official e-filing site to lure laymen, said the report. (IANS/SP)



Most Popular

Nanking Massacre: The Holocaust

By- Khushi Bisht The Nanking Massacre, also known as the Rape of Nanking, was one of the worst massacres committed during the Sino-Japanese war that...

‘Child Of Two Worlds’ Featuring The Protagonists And Immortal Lovers

Turkey-based author Ann D'Silva has launched her new book "Child of Two Worlds", which is second in the fictional 'Sand and Sea' series, which...

Now Transfer Posts And Notes To Google Docs And WordPress Directly

Facebook on Monday introducing two new data portability types that will help users directly transfer their posts and notes to Google Documents, Blogger, and...

Lyricist Mehboob: The Line Between Film Music And Indie Music Has Blurred Lately

The line between film music and indie music has blurred lately, feels noted lyricist Mehboob, who has over 25 years of experience in the...

OTT Projects Based On Books

With OTT platforms experimenting with genres and content, there are a host of projects that are based on books. Lately, we have already had...

Something Screened On Your Phone Can Not Erase A Huge Screen, Says Boman Irani

Good writing is the need of the hour, feels actor Boman Irani, to sustain audience interest at a time when OTT provides a surfeit...

The Truth Behind Why Airliners Don’t Fly Over Tibet

BY- JAYA CHOUDHARY Airplanes can fly for thousands of kilometers across the globe. Rockets have landed men on the moon and Elon Musk plans to...

Symptoms Affecting Daily Life Post Covid Recovery

Are you a Covid-19 survivor, but still feel fatigued and not having fully recovered? You may be experiencing what is known as "Long Covid"....

Recent Comments