HDFC eChallan RAT
Malware family · 3 sample(s) · 6 indicator record(s) · 3 signing certificate(s) · Active 2026-07-23 → 2026-10-04 (experimental)
About HDFC eChallan RAT
India-targeted netbanking RAT distributed with a fake RTO traffic e-challan (“eChallan”) lure impersonating HDFC. A three-stage packer (XOR + AES-CBC + gunzip, loaded via InMemoryDexClassLoader with an on-device self-signing installer) drops an SMS-stealing banking trojan that harvests netbanking/UPI/card credentials and OTP SMS. Stolen data is exfiltrated to attacker Firebase Realtime Database instances; a bundled VpnService routes device DNS through attacker resolvers (seen as IP indicators such as 108.74.33.9 and 201.92.30.6).
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| baccha-a07d9-default-rtdb.firebaseio.com | domain | 021d92dd0026… | 2026-07-23 |
| motupatlu-7638e-default-rtdb.firebaseio.com | domain | 526657e1fc1d… | – |
| sukhdev001-68bfd-default-rtdb.firebaseio.com | domain | 20e41f8c7d50… | 2026-10-04 |
| sukhdev001-68bfd-default-rtdb.firebaseio.com | domain | 526657e1fc1d… | 2026-07-31 |
| 108.74.33.9 | ip | 20e41f8c7d50… | 2026-10-04 |
| 201.92.30.6 | ip | 20e41f8c7d50… | 2026-10-04 |