Skip to content
ThreatCluster

KYCShadow Malware Targets Indian Bank Customers via WhatsApp

First seen 28 Apr 2026, 09:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 29, 2026 at 08:39 UTC
  • •KYCShadow malware targets Indian bank customers through fake KYC workflows.
  • •The malware is distributed via WhatsApp as a malicious APK posing as a legitimate app.
  • •Victims are tricked into providing sensitive financial credentials unknowingly.

A new Android banking malware known as KYCShadow has emerged, specifically targeting bank customers in India. The malware exploits a fake Know Your Customer (KYC) verification process and is distributed through WhatsApp messages. Victims receive messages urging them to install a malicious APK that masquerades as an official banking compliance application. Once installed, KYCShadow silently collects sensitive financial information from the users. This campaign is part of a broader trend of banking fraud in India, similar to previous incidents. The malware's distribution method and social engineering tactics make it particularly dangerous. As of now, there are no reported figures on the number of victims or financial losses. Security experts are urging users to be cautious of unsolicited messages regarding KYC updates. The situation is ongoing, with no specific countermeasures reported yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 165d ago How this analysis works

Timeline

2026-04-28
KYCShadow malware discovered and reported in multiple articles.

More articles in this cluster (2)

Following this threat?

Track KYCShadow in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed