UPI OTP Stealer (provisional)

Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s) · Active 2026-10-07 (experimental)

About UPI OTP Stealer (provisional)

India-targeted Android banking stealer focused on UPI (Unified Payments Interface) fraud. Delivered as a dropper, it abuses SMS access to intercept one-time passcodes and harvests UPI/banking credentials, exfiltrating them to its backend (observed at deploy229.cehtech.net). Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
deploy229.cehtech.net domain f720caa316e6… 2026-10-07