UPI OTP Stealer (provisional)
Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s) · Active 2026-10-07 (experimental)
About UPI OTP Stealer (provisional)
India-targeted Android banking stealer focused on UPI (Unified Payments Interface) fraud. Delivered as a dropper, it abuses SMS access to intercept one-time passcodes and harvests UPI/banking credentials, exfiltrating them to its backend (observed at deploy229.cehtech.net). Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| deploy229.cehtech.net | domain | f720caa316e6… | 2026-10-07 |