/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Android trojan Drinik targets users of 18 Indian banks, masquerading as the country's official tax management app to steal personal data and banking credentials

Bill Toulas / BleepingComputer :

BleepingComputer Bill Toulas

Context & Ripple Effects

Drinik is the latest entry in a well-documented lineage of Android banking trojans that borrow trusted identities to reach victims' wallets. Earlier coverage showed [[a:973427|credential-stealing apps on Google Play disguised as QR scanners, PDF tools, and crypto wallets]], and malware like Godfather later industrialized the approach with overlaid login screens across 400+ banking apps in 16 countries.

What distinguishes this campaign is the disguise: impersonating India's own official tax management app gives the trojan a pretext no third-party brand can match, since users expect to hand that app personal and financial data. It extends a pattern where attackers stopped mimicking banks directly and started mimicking the state instead.

First-order effects

  • Customers of the 18 targeted Indian banks who install the fake tax app expose personal data and banking credentials directly to the operators, with fraudulent transfers the likely immediate use.
  • The named banks absorb the fallout now: fraud investigations, customer reimbursement, and support load, while their own apps did nothing wrong.

Second-order effects

  • Indian banks are pushed to harden against a threat their app-level defenses can't see — device-side malware holding valid credentials — accelerating adoption of out-of-band verification and behavioral fraud detection.
  • Google faces renewed pressure over Play Store vetting, since related campaigns like Anatsa repeatedly slipping through as a PDF viewer show the review process is a recurring weak point rather than a one-off failure.

Third-order effects

  • If impersonating official government apps proves effective, the trust boundary for mobile finance shifts: banks can no longer assume an app that looks governmental is safe, pushing the industry toward attestation and verified-app channels.
  • The escalation chain visible across this coverage — overlays (Godfather), OTP extraction (Cerberus), biometric disruption (Chameleon) — points toward Android banking security becoming an arms race decided by platform-level controls, not per-app fixes.

The trend: Android banking trojans are escalating from mimicking bank apps to hijacking the credibility of official government apps, making platform-level identity verification the next battleground.