CYBERRAKSHAK LABS · RESEARCH #012

🚨 FAKE TRAFFIC CHALLAN → MALICIOUS APK

CyberRakshakLabs analysis of a fake traffic-challan SMS campaign delivering a malicious Android APK impersonating mParivahan, with indicators of compromise and defensive actions.

By Vivek Kumar · Published 26 August 2026
RESEARCH#012
CATEGORYPhishing & Social Engineering
CRL ASSESSMENTHIGH
RESEARCH LEVELThreat Alert
PUBLISHED2026-08-26

What I Found During My Analysis

The Attack Chain

Why the Scam Works

The Fake Website
  • During the investigation, the SMS redirected to mparivahan-gov.dedyn.io.
  • The supplied post identifies echallan.parivahan.gov.in as the official eChallan service and explains that the fake site was designed to visually resemble an official application listing using government/NIC-style branding.
  • The attack is a combination of Brand Impersonation + Phishing + Malware Delivery.
Technical Analysis — APK
  • Filename: NextGen_mParivahan._apk.apk
  • Type: Android APK
  • Size: ~6.89 MB / 7,224,764 bytes
  • MD5: fdad41a9659f151f2bf4c1df80b20454
  • SHA-1: ecdc5f6eec08ee1d8a1dd1bca67612e1feb30ba7
  • SHA-256: ad8b3644fb48c312932454a378c1ece19811b7c8891785fed51e6547db4451d5
  • VirusTotal observation: 8 / 64 security vendors flagged the sample as malicious.
  • The APK contains three DEX files: classes.dex, classes2.dex and classes3.dex.
  • Approximately 938 ZIP/APK entries were observed during static inspection.
  • The package also contains an asset associated with ApkControlFlowConfusion_8.0, consistent with code-obfuscation/protection tooling.
  • Static inspection alone does not establish every runtime capability. The safest conclusion from the available evidence is that the sample is suspicious/malicious and should not be installed.
This Is Not Just a “Fake Challan” Scam
  • The danger is the APK installation.
  • A phishing website can steal credentials. A malicious Android application can potentially obtain access to sensitive device functionality depending on the permissions granted and the implementation of the malware.
  • Potential targets may include banking credentials, SMS/OTP, calls, contacts, notifications, payment information, authentication data and personal files.
  • The exact capabilities depend on the malware’s permissions and runtime behaviour.

Red Flags in This Incident

How to Protect Yourself
  • 1. Never install APKs from SMS links. Government challan ≠ APK download from an SMS link.
  • 2. Check your challan yourself. Do not use the link provided in the SMS. Open the official eChallan service independently and enter your vehicle/challan details there.
  • 3. Don’t trust the app logo. A malicious APK can copy the logo, name, screenshots, description and government branding. Verify the source, not the appearance.
  • 4. Keep “Install unknown apps” disabled. Review which applications have permission to install unknown applications and keep the setting disabled when you do not need it.
If You Already Installed the APK
  • Treat the device as potentially compromised.
  • Disconnect from the internet if active compromise is suspected.
  • Remove the malicious application.
  • Change important passwords from a clean device.
  • Contact your bank if financial information may have been exposed.
  • Review SMS, call and notification activity.
  • Check installed applications and special permissions.
  • Monitor bank and UPI transactions.
  • Preserve the SMS, URL and APK as evidence.
  • If financial fraud has already occurred in India, report it immediately through 1930 and the National Cyber Crime Reporting Portal.

The Biggest Lesson

IOC — Indicators of Compromise
  • Malicious APK: NextGen_mParivahan._apk.apk
  • SHA-256: ad8b3644fb48c312932454a378c1ece19811b7c8891785fed51e6547db4451d5
  • SHA-1: ecdc5f6eec08ee1d8a1dd1bca67612e1feb30ba7
  • MD5: fdad41a9659f151f2bf4c1df80b20454
  • Suspicious domain: mparivahan-gov.dedyn.io
  • Observed URL: https://mparivahan-gov.dedyn.io/558489/
  • Delivery Vector: SMS → Fake eChallan page → Malicious APK
🛡️ CyberRakshakLabs Security Message

A REAL CHALLAN DOES NOT REQUIRE YOU TO TRUST A RANDOM APK.

STOP → DON'T CLICK → DON'T INSTALL APK → OPEN THE OFFICIAL eChallan PORTAL YOURSELF → VERIFY

Open Official eChallan Portal ↗

Connect with CyberRakshakLabs
Original LinkedIn Post YouTube Short WhatsApp Post