Urgent Security Alert

New 'Digital Vulture' Malware Targeting Indian Banking Apps

A sophisticated new Android malware is actively targeting users of major Indian banks. Here’s what you need to know to protect your finances immediately.

Published: September 12, 2025


Cybersecurity researchers have issued a high-priority alert regarding a new strain of Android malware, codenamed 'Digital Vulture'. This malicious software is specifically designed to steal banking credentials from users across India by creating fake login screens for popular financial apps. The attack is spreading rapidly through SMS and third-party app stores.

A smartphone screen showing a security alert

How Does the 'Digital Vulture' Malware Work?

The malware primarily spreads through phishing messages (smishing) that trick users into downloading a malicious app (APK file) from outside the Google Play Store. These messages often promise a refund, a KYC update, or a special offer. Once installed, the malware operates silently in the background:

  • It scans the device for the presence of legitimate Indian banking and UPI apps.
  • When you open a targeted app, the malware instantly creates an identical fake login screen (an overlay) on top of the real app.
  • You unknowingly enter your username, password, or PIN into the fake screen.
  • The malware captures these credentials and sends them to the attackers, giving them full access to your bank account.

Key Apps Targeted in India

While the list is growing, initial reports confirm that the malware targets customers of the following major banks:

  • State Bank of India (Yono SBI)
  • HDFC Bank MobileBanking
  • ICICI Bank (iMobile Pay)
  • Axis Mobile
  • Paytm
  • PhonePe
  • Google Pay (GPay)
  • Punjab National Bank (PNB ONE)

What To Do Immediately

If you suspect your device might be infected or have recently downloaded an app from an unknown source, take these steps right now:

  • 1. Disconnect Your Device

    Immediately turn off Wi-Fi and mobile data to prevent the malware from communicating with the attackers.

  • 2. Check Your Bank Accounts

    Using a different, trusted device (like a laptop), log in to your bank accounts and check for any unauthorized transactions. Report any suspicious activity to your bank's fraud department instantly.

  • 3. Remove the Malicious App

    Boot your phone into 'Safe Mode' (this varies by manufacturer). In Safe Mode, go to Settings -> Apps and uninstall any suspicious or recently installed applications that you don't recognize.

  • 4. Consider a Factory Reset

    For complete peace of mind, the most effective solution is to perform a full factory reset of your device. This will erase all data, including the malware. Ensure you have backed up your important files (photos, contacts) beforehand.

How to Stay Protected

  • NEVER download apps from links in SMS or WhatsApp. Only use the official Google Play Store.
  • Be skeptical of urgent messages. Banks will never ask for sensitive information via text message.
  • Install a reputable mobile security app from a trusted brand to scan for threats.
  • Keep your phone's operating system and all apps updated.