Skip to content
Fake Cockroach Janta Party apps flagged as critical android malware threat: TraceX Labs report

Fake Cockroach Janta Party apps flagged as critical android malware threat: TraceX Labs report

Adgully May 25, 2026

Cyber intelligence firm TraceX Labs has issued a critical security advisory warning Android users against a malicious Remote Access Trojan (RAT) masquerading as the official application for the popular GenZ political organization, the "Cockroach Janta Party".

The security alert explicitly notes that the legitimate political party has no affiliation with this software and is a victim of criminal brand impersonation. Threat actors are weaponizing the group's popularity to trick supporters into compromising their smartphones.

According to the forensic report, the ~5 MB malicious package (Cockroach.Janta.Party) is spreading rapidly across India via three primary infection vectors. The infected file (Cockroach Janta Party.apk) is being side-loaded and forwarded manually via lookalike WhatsApp chains and specialized Telegram community groups. Also, attackers are driving web traffic to a rogue domain, cockroachjantaparty[.]org, which mirrors the party’s visual branding to offer direct, untrusted app downloads.

Once side-loaded onto a target system running Android 8.0 to 14, the Trojan prompts users for critical operational permissions under a deceptively simple user interface.

A successful exploit grants the hacker total remote control of the mobile device by tricking the user into enabling Android’s Accessibility permissions. The malware gains the ability to record on-screen text, capture active passwords, intercept two-factor banking OTPs, and simulate phantom screen clicks without user knowledge.

Automated code routines actively parse, bundle, and steal system books, historical call logs, local text messages, and full camera rolls.

To avoid triggering behavioral security flags, the Trojan handles command-and-control (C2) reporting by sending encrypted outbound data streams via standard HTTPS requests directly to a hidden Telegram Bot API network. This allows malicious exfiltration traffic to hide undetected within everyday web browsing data.

Security teams have classified the threat level as critical due to the high risk of immediate financial fraud and credential theft.

If a user discovers the fake "Cockroach Janta Party" application installed on their device, cybersecurity experts mandate the following sequential defense checklist:

Disconnect Access: Navigate to Android Settings, open Accessibility Settings, and toggle the permissions for any service related to the application to OFF .

Purge the App: Immediately locate the package within your Application Manager and execute a hard uninstall.

Lock Down Accounts: Using a separate, uninfected electronic device, immediately change all active online banking credentials and shift two-factor profiles from standard SMS verification to a dedicated authenticator app.

TraceX Labs has uploaded identified file hashes and automated YARA scanning signatures to the global defensive community, while formal threat notices have been submitted to Telegram and domain registrars to disable the attacker's server infrastructure.

Readers can access the whole report here : Cockroach Janta Party Malware Threat Report 2026

DoubleVerify delivers global media quality measurement for audience network

How Synology is building the data foundation for an AI-driven world

Google I/O 2026 puts Gemini at the centre of Its agentic AI push

Google expands AI education initiatives for teachers and students in India

AnyMind Group opens Japan market gateway for Indian brands with launch of AI-powered ‘AnyAI OMO’

Are brands over investing in technology and under investing in creativity?

HuellaNXT brings creative intelligence into programmatic advertising

Mobavenue AI Tech reports FY2026 revenue of Rs. 218 crores

The Rise of Free Streaming in India: Why FAST Channels Are Winning Viewer Loyalty

How AI Is Reshaping Recruitment for Creative, Digital & Media Roles