Skip to main content
New: Free scam checker — paste any SMS and find out in seconds Try it →

Fake apps and APKs: the file that reads your OTPs

Do not install an APK file sent to you over WhatsApp, Telegram or SMS, whatever it claims to be. Apps that arrive as files bypass the Play Store's checks entirely, and the permission they ask for most often is access to your SMS — which is where your OTPs are. An app that can read your OTPs can move your money without you ever seeing a code.

A fake "system critical, security update needed" SMS with an APK download link, and the sequence beneath it: SMS received, APK downloaded, permissions granted, phone hacked and funds stolen.

How it plays out

The wedding invitation from a number he had saved

The file arrives on WhatsApp from a cousin's number, with the message everyone sends: "Invitation attached, do come." The file is called something like Wedding_Invitation.apk. He taps it, Android warns him that installing from this source is not allowed, and he allows it, because the invitation is from family.

The app opens on a card that never finishes loading. While he waits, it asks to read SMS and to display over other apps. He grants both, the way anyone grants a permission prompt standing between them and the thing they opened the app for.

Nothing happens for two days. Then, on the Thursday, ₹48,000 leaves the account in four transactions. No OTP arrived on the phone — not because none was sent, but because the app read each one and hid the message.

His cousin never sent an invitation. The same file had been going out from that phone, to everyone in the contact list, for a week.

₹48,000 in four transactions he was never notified of, from a phone that showed no OTP and no alert.

A composite of the malicious-APK pattern as described in Indian police cyber-cell advisories and Android security research on the wedding-invitation campaigns, including the SMS-reading and screen-overlay permissions and the self-forwarding behaviour. No real person or case is depicted; the amount is illustrative.

Where it could have stopped

The permission screen. A wedding invitation has no reason to read SMS or to draw over other apps, and that mismatch — between what an app claims to be and what it asks for — is visible before any harm is done. Denying it, or not installing a file from a chat at all, ends this scam entirely.

EnfoldAIHigh risk

What EnfoldAI does here

Fake app & APK detection

This is the file EnfoldAI is built to catch. The app checks APKs before you install them, so the invitation is flagged as a fake app at the prompt — and the SMS that carries one is marked as a scam in your inbox before you ever reach the file.

Checks APKs before you install.

Auto-check with EnfoldAI

How this scam works

The order is the explanation. Find where your own experience stops in this list — that is how far along the script has run.

  1. A file arrives on WhatsApp with a name that explains itself: a wedding invitation, an electricity-bill update, a bank KYC app, a courier tracker, an RTO challan app, a school notice.
  2. It is an APK — an installable Android app — not a document. Opening it asks Android to allow installation from an unknown source, and that prompt is the last real defence.
  3. On first run it asks for permission to read SMS, to show over other apps, to use accessibility services, or to act as the default messaging app. Granting any of those hands over your one-time passwords or your screen.
  4. From then on, transactions can be authorised without you seeing the OTP at all: the app intercepts the message and can hide it. This is why the money often appears to leave with no alert of any kind.
  5. Some variants add screen overlay, so a fake login screen sits on top of your real banking app and captures what you type into it.
  6. Others install a remote-access tool, which gives an operator the phone itself — the banking app, the gallery, the contacts — rather than just the messages.
  7. The file spreads by sending itself onward to your contacts from your phone, which is why it usually arrives from someone you know. A file from a trusted contact is the normal case here, not the exception.
  8. There is often a delay of a day or more between installation and the first transaction, so the two do not feel connected.

If it has already happened

In order, and the order matters. The first step is the one that can still get the money held, so it comes before everything else.

  1. Put the phone in aeroplane mode to cut the app off while you work through the rest.
  2. Uninstall the app. If it has no icon, look under Settings, then Apps, and sort by recently installed; if it cannot be removed, it may hold device-admin or accessibility rights that must be revoked under Settings first.
  3. Call your bank on the number on your debit card and ask them to block cards and net-banking, and to watch for transactions you did not authorise.
  4. Change your UPI PIN, net-banking password and email password from a different device.
  5. Report on 1930 or at cybercrime.gov.in, and tell whoever sent you the file, because their phone is sending it.
  6. If anything remains unclear afterwards, a factory reset is the reliable end state. Back up photos and documents only, never apps.

Fake apps and APKs — common questions

The questions people actually ask about this one, answered in a line or two each.

What is an APK, and why is one in my chat a problem?
An APK is an installable Android app. One sent in a chat skips the Play Store's screening entirely, so nothing has checked what it does before you run it.
Why does it ask to read my SMS?
Because your one-time passwords arrive there. An app that reads SMS can approve transactions without you ever seeing the code.
Money left my account and I never got an OTP. How?
An app with SMS permission can read the code and hide the message. The OTP was sent; the app took it before you saw it.
It came from a friend. Is it safe?
No. These files forward themselves from infected phones, so arriving from someone you know is the normal case, not an exception.
See all scams →