Fake apps and APKs: the file that reads your OTPs
Do not install an APK file sent to you over WhatsApp, Telegram or SMS, whatever it claims to be. Apps that arrive as files bypass the Play Store's checks entirely, and the permission they ask for most often is access to your SMS — which is where your OTPs are. An app that can read your OTPs can move your money without you ever seeing a code.

How it plays out
The wedding invitation from a number he had saved
The file arrives on WhatsApp from a cousin's number, with the message everyone sends: "Invitation attached, do come." The file is called something like Wedding_Invitation.apk. He taps it, Android warns him that installing from this source is not allowed, and he allows it, because the invitation is from family.
The app opens on a card that never finishes loading. While he waits, it asks to read SMS and to display over other apps. He grants both, the way anyone grants a permission prompt standing between them and the thing they opened the app for.
Nothing happens for two days. Then, on the Thursday, ₹48,000 leaves the account in four transactions. No OTP arrived on the phone — not because none was sent, but because the app read each one and hid the message.
His cousin never sent an invitation. The same file had been going out from that phone, to everyone in the contact list, for a week.
₹48,000 in four transactions he was never notified of, from a phone that showed no OTP and no alert.
A composite of the malicious-APK pattern as described in Indian police cyber-cell advisories and Android security research on the wedding-invitation campaigns, including the SMS-reading and screen-overlay permissions and the self-forwarding behaviour. No real person or case is depicted; the amount is illustrative.
Where it could have stopped
The permission screen. A wedding invitation has no reason to read SMS or to draw over other apps, and that mismatch — between what an app claims to be and what it asks for — is visible before any harm is done. Denying it, or not installing a file from a chat at all, ends this scam entirely.
What EnfoldAI does here
Fake app & APK detection
This is the file EnfoldAI is built to catch. The app checks APKs before you install them, so the invitation is flagged as a fake app at the prompt — and the SMS that carries one is marked as a scam in your inbox before you ever reach the file.
Checks APKs before you install.
Auto-check with EnfoldAIHow this scam works
The order is the explanation. Find where your own experience stops in this list — that is how far along the script has run.
- A file arrives on WhatsApp with a name that explains itself: a wedding invitation, an electricity-bill update, a bank KYC app, a courier tracker, an RTO challan app, a school notice.
- It is an APK — an installable Android app — not a document. Opening it asks Android to allow installation from an unknown source, and that prompt is the last real defence.
- On first run it asks for permission to read SMS, to show over other apps, to use accessibility services, or to act as the default messaging app. Granting any of those hands over your one-time passwords or your screen.
- From then on, transactions can be authorised without you seeing the OTP at all: the app intercepts the message and can hide it. This is why the money often appears to leave with no alert of any kind.
- Some variants add screen overlay, so a fake login screen sits on top of your real banking app and captures what you type into it.
- Others install a remote-access tool, which gives an operator the phone itself — the banking app, the gallery, the contacts — rather than just the messages.
- The file spreads by sending itself onward to your contacts from your phone, which is why it usually arrives from someone you know. A file from a trusted contact is the normal case here, not the exception.
- There is often a delay of a day or more between installation and the first transaction, so the two do not feel connected.
If it has already happened
In order, and the order matters. The first step is the one that can still get the money held, so it comes before everything else.
- Put the phone in aeroplane mode to cut the app off while you work through the rest.
- Uninstall the app. If it has no icon, look under Settings, then Apps, and sort by recently installed; if it cannot be removed, it may hold device-admin or accessibility rights that must be revoked under Settings first.
- Call your bank on the number on your debit card and ask them to block cards and net-banking, and to watch for transactions you did not authorise.
- Change your UPI PIN, net-banking password and email password from a different device.
- Report on 1930 or at cybercrime.gov.in, and tell whoever sent you the file, because their phone is sending it.
- If anything remains unclear afterwards, a factory reset is the reliable end state. Back up photos and documents only, never apps.
Fake apps and APKs — common questions
The questions people actually ask about this one, answered in a line or two each.
What is an APK, and why is one in my chat a problem?
Why does it ask to read my SMS?
Money left my account and I never got an OTP. How?
It came from a friend. Is it safe?
Check before you trust
Paste any SMS, link or app and get a verdict before money moves. Auto-scan flags scam messages the moment they arrive.
Suspicious message? Check it free →