Android trojan Drinik targets users of 18 Indian banks, masquerading as the country's official tax management app to steal personal data and banking credentials
Bill Toulas / BleepingComputer :
Context & Ripple Effects
Drinik is the latest entry in a well-documented lineage of Android banking trojans that borrow trusted identities to reach victims' wallets. Earlier coverage showed [[a:973427|credential-stealing apps on Google Play disguised as QR scanners, PDF tools, and crypto wallets]], and malware like Godfather later industrialized the approach with overlaid login screens across 400+ banking apps in 16 countries.
What distinguishes this campaign is the disguise: impersonating India's own official tax management app gives the trojan a pretext no third-party brand can match, since users expect to hand that app personal and financial data. It extends a pattern where attackers stopped mimicking banks directly and started mimicking the state instead.
First-order effects
- Customers of the 18 targeted Indian banks who install the fake tax app expose personal data and banking credentials directly to the operators, with fraudulent transfers the likely immediate use.
- The named banks absorb the fallout now: fraud investigations, customer reimbursement, and support load, while their own apps did nothing wrong.
Second-order effects
- Indian banks are pushed to harden against a threat their app-level defenses can't see — device-side malware holding valid credentials — accelerating adoption of out-of-band verification and behavioral fraud detection.
- Google faces renewed pressure over Play Store vetting, since related campaigns like Anatsa repeatedly slipping through as a PDF viewer show the review process is a recurring weak point rather than a one-off failure.
Third-order effects
- If impersonating official government apps proves effective, the trust boundary for mobile finance shifts: banks can no longer assume an app that looks governmental is safe, pushing the industry toward attestation and verified-app channels.
- The escalation chain visible across this coverage — overlays (Godfather), OTP extraction (Cerberus), biometric disruption (Chameleon) — points toward Android banking security becoming an arms race decided by platform-level controls, not per-app fixes.
The trend: Android banking trojans are escalating from mimicking bank apps to hijacking the credibility of official government apps, making platform-level identity verification the next battleground.