Quick Reply: Installed a “wedding card / e-bill / KYC” APK on WhatsApp? Detect the trojan in 60 seconds, factory-reset safely, recover money under RBI 2017 rules — 2026 playbook.
“Wedding card_invitation.apk”, “Electricity_bill.apk”, “KYC_update.apk”, “Income_tax_notice.apk” — these are the highest-volume Android trojans circulating on WhatsApp in 2026. They spawn an invisible window that intercepts every OTP, takes over WhatsApp, and drains UPI in minutes. This page tells you how to detect installation, clean the device safely, and recover under RBI rules.
Citizen Crisis Response Network — APK rule
Never install a ``.apk`` file received over WhatsApp, Telegram, email, or SMS — even if it appears to come from a relative. All legitimate Indian apps live on the Play Store / App Store / banks' verified domains.
If you installed a ``.apk`` file received over WhatsApp / email / Telegram / SMS in India: (1) immediately switch the phone to airplane mode, (2) revoke Accessibility Service permission for any unknown app via Settings → Accessibility, (3) uninstall the suspicious app + factory-reset the phone after backing up only photos and contacts, (4) call 1930 and file at cybercrime.gov.in if any banking activity is suspected, (5) change net-banking + email + WhatsApp passwords from a different device, and (6) email your bank within 24 hours under RBI's 2017 framework. Recovery probability is highest within the first 90 minutes.
The defining permission ask: Accessibility Service. No legitimate non-screen-reader app needs it.
If even one suspicious entry appears, treat the device as compromised and run the cleanup drill below.
If banking activity has occurred between installation and detection:
Steps:
To, The Branch Manager, [Bank Name], [Branch], [City] Subject: Unauthorised debit / banking trojan via .apk install — A/C [last 4 digits] — request for refund under RBI Master Direction 2017 Sir / Madam, I, [Full name], holder of Savings A/C [number], wish to report unauthorised debit(s) totalling ₹[amount] on [date] at approximately [time], arising from a malicious Android Application Package (.apk) that I installed in good faith on [date] at [time]. Transactions affected: [Date] [Time] [UTR / Ref] [Amount] [Beneficiary] ... Actions already taken: 1. Airplane mode + accessibility revocation + factory reset 2. Net-banking + email + WhatsApp passwords reset 3. Debit card blocked 4. 1930 complaint (Reference: ___) 5. cybercrime.gov.in submission (Reference: ___) 6. CIBIL report pulled (Reference: ___) I report within ___ working day(s) of the unauthorised debit. Per RBI's Master Direction on Limiting Liability of Customers, 2017, my liability is [Zero / capped at ₹5,000]. I request you to: a) Credit a temporary / shadow amount within 10 working days. b) Resolve the dispute within 90 days. c) Reply in writing. Yours faithfully, [Signature, Name, Date, Phone, Email]
If this complaint isn't resolved through the regular complaint route, you can file an RTI to force the public authority to either act or explain in writing why they haven't. The fee is ₹10 (free if you're BPL).
With SMS-read permission + Accessibility, the trojan reads every incoming SMS and forwards via HTTPS to its command server.
Sometimes yes (the well-known families) and sometimes no (custom trojans). Don't rely on Play Protect; rely on never installing an APK from chat.
If you only opened the file but didn't install, no. If you installed and granted permissions, yes — it's the only certain cleanup.
Not directly, but credentials it captured (email, banking) work on any device.
Shadow / temporary credit within 10 working days; full resolution within 90 days. RB-IOS escalates if delayed.
| Myth | Reality |
|---|---|
| “APK from a friend is safe.” | The friend's phone may itself be compromised; the file is the threat, not the sender. |
| “Antivirus will catch it.” | Custom trojans evade most AV. Factory reset is the safe fix. |
| “If I uninstall, I'm clean.” | Trojans abuse Device Admin and persist. |
| “Banks won't refund a self-installed APK loss.” | RBI 2017 frames this as deceit-based unauthorised transaction; refund is the rule. |
| “I'll lose all my data on factory reset.” | Photos / contacts / Drive sync are recoverable. Apps re-install from store. |
Fake APK installation scam in India — complete guide on identification, prevention, and reporting:
See Fake APK Scam and Dating App Blackmail Scam.