Differences
This shows you the differences between two versions of the page.
| — | fake-app-installed-phone-removal-bank-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | |||
| + | ====== Fake app installed on your phone: how to remove and protect bank ====== | ||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP info> | ||
| + | **Quick Reply:** Put the phone on **airplane mode** in the next 60 seconds. Then boot into **Safe Mode**, uninstall the suspicious app (and any " | ||
| + | </ | ||
| + | |||
| + | You probably found this page because a banking SMS just landed that you did not expect, or because a relative phoned to say "I installed an app and now the app store says my phone is compromised" | ||
| + | |||
| + | ===== Why a fake app is more dangerous than a phishing SMS ===== | ||
| + | |||
| + | A phishing SMS asks you to type a password, you can refuse. A fake app, once installed and granted the wrong permissions, | ||
| + | |||
| + | The five families of fake apps you will encounter: | ||
| + | |||
| + | - **Sideloaded APKs** sent over WhatsApp or Telegram, often dressed as a wedding invite, a courier slip, an electricity-bill helper, or an " | ||
| + | - **Remote-access apps** like AnyDesk, TeamViewer QuickSupport and similar, installed at the request of a fake "bank manager" | ||
| + | - **Fake bank apps** that mimic the real bank's name and icon, harvested from a clone listing on a third-party store | ||
| + | - **Fake loan apps** that demand contacts and gallery access on first launch, then blackmail you with morphed photos | ||
| + | - **Fake government apps** posing as DigiLocker, mParivahan, Income Tax, EPFO, IRCTC or a state grievance portal | ||
| + | |||
| + | The damage path is the same in each case: the app obtains **accessibility service** access, **SMS read** access, or **screen-overlay** permission. Once it has any one of those, it can quietly drain a bank account inside ten minutes. This is why we treat every minute as urgent. | ||
| + | |||
| + | ===== Step 0 (do this now, in under 60 seconds) ===== | ||
| + | |||
| + | Before you read another word, do these three things on the affected phone: | ||
| + | |||
| + | - Slide down the notification shade and tap the **airplane mode** icon. This kills mobile data, Wi-Fi and SMS in one tap. | ||
| + | - Yank the **SIM card** out if airplane mode is unreliable on your model. A paperclip will pop the tray on most phones. | ||
| + | - Plug the phone in. You will need battery. | ||
| + | |||
| + | Airplane mode is the single most powerful defensive move you have. A fake app cannot exfiltrate, cannot accept push OTPs, cannot talk to its command server, and cannot relay anything to the attacker while the radios are off. Keep airplane mode on until step 6. | ||
| + | |||
| + | ===== The 30-minute emergency action plan ===== | ||
| + | |||
| + | Read the whole plan once, then start at step 1. Do not skip steps even if you think a step does not apply. | ||
| + | |||
| + | ==== Step 1: Identify what you installed (3 minutes) ==== | ||
| + | |||
| + | Open **Settings → Apps** (Android) or **Settings → General → iPhone Storage** (iOS) and scroll the full list. You are looking for: | ||
| + | |||
| + | - Any app installed in the last 48 hours that you do not remember installing | ||
| + | - Any app called **AnyDesk**, | ||
| + | - Any banking, loan or government-looking app whose **publisher name** you cannot recognise | ||
| + | - Any app whose **install source** is not Google Play or App Store (Android: "App details" | ||
| + | |||
| + | Take a screenshot of each suspicious entry. You will need the package name later for the cyber complaint. | ||
| + | |||
| + | ==== Step 2: Cut the app's powers BEFORE uninstalling (4 minutes) ==== | ||
| + | |||
| + | Some fake apps refuse to uninstall by trapping the back-button using their accessibility service. You have to disarm them first. | ||
| + | |||
| + | - Go to **Settings → Accessibility → Installed services** (Android) or **Settings → Accessibility** (iOS). Switch off any service belonging to the suspicious app. | ||
| + | - Go to **Settings → Apps → Special app access → Display over other apps** and disable the suspicious app's overlay permission. | ||
| + | - Go to **Settings → Apps → Special app access → Device admin apps** and revoke any device-admin rights the app holds. A fake app with device-admin rights can stop you uninstalling it, you must take this away first. | ||
| + | - On iOS, go to **Settings → General → VPN & Device Management** and remove any unknown configuration profile. | ||
| + | |||
| + | ==== Step 3: Boot into Safe Mode and uninstall (5 minutes) ==== | ||
| + | |||
| + | Safe Mode disables every third-party app at boot. Even an app that has hidden its icon and intercepted button taps will be inert in Safe Mode. The exact key combination differs by phone: | ||
| + | |||
| + | - **Stock Android**, Pixel, Motorola, Nokia: hold power, long-press "Power off" until " | ||
| + | - **Samsung Galaxy**: hold power, tap and hold "Power off" until the Safe Mode icon appears. | ||
| + | - **Xiaomi, Redmi, POCO (HyperOS / MIUI)**: hold power, then volume-down at the boot logo, hold until "Safe Mode" shows in the bottom-left corner. | ||
| + | - **OnePlus, Realme, Oppo, Vivo**: hold power and volume-down together at the boot logo. | ||
| + | - **iPhone**: iOS does not have a Safe Mode in the Android sense. Instead, force-restart (volume up, volume down, hold side button) and uninstall the app from the home screen. | ||
| + | |||
| + | In Safe Mode, the screen will show a "Safe mode" watermark at the bottom. Open **Settings → Apps → All apps**, find each suspicious entry, tap **Uninstall**. If " | ||
| + | |||
| + | Reboot normally only after every flagged app is gone. | ||
| + | |||
| + | ==== Step 4: Freeze the bank channel from a CLEAN device (4 minutes) ==== | ||
| + | |||
| + | Use a second device (a spouse' | ||
| + | |||
| + | Tell the operator: "I have unknowingly installed a fake app on my phone. Please **freeze all debit and credit cards**, **disable UPI**, **disable net-banking** and **block my registered mobile number for OTP delivery** pending verification. I will visit the branch in person to re-enable." | ||
| + | |||
| + | If the bank refuses to freeze without an FIR, push back. The Reserve Bank of India' | ||
| + | |||
| + | ==== Step 5: Dial 1930 and lodge the NCRP complaint (5 minutes) ==== | ||
| + | |||
| + | If any money has already moved or if the attacker had remote-access time on your phone (even without a confirmed debit yet), dial **1930** from the clean device. This is the **National Cyber Crime Helpline** run by I4C. The operator can request a **temporary lien** on the beneficiary account if your money was already routed. Keep your bank account number, the time of installation, | ||
| + | |||
| + | After the call, file the written complaint at **https:// | ||
| + | |||
| + | For a full minute-by-minute helpline script, jump to [[1930-helpline-cyber-fraud-script|the 1930 helpline script]]. For the legal mechanics of the bank freeze, see [[bank-freeze-cyber-fraud-india|how a bank freezes a cyber-fraud beneficiary account]]. | ||
| + | |||
| + | ==== Step 6: Clean up the phone (8 minutes) ==== | ||
| + | |||
| + | Now the bank is locked down and the cyber complaint is in. You can come off airplane mode on the affected phone, but cautiously: | ||
| + | |||
| + | - Run **Google Play Protect**: open the Play Store, tap your profile picture, tap "Play Protect", | ||
| + | - Reset your **Google account password** from a clean device at https:// | ||
| + | - Reset your **Apple ID password** from a clean device at https:// | ||
| + | - Check **Settings → Apps → Default apps → Browser app** and reset any browser hijack. | ||
| + | - Check **Settings → Notifications → Notification access** and revoke notification-listener access from anything you do not recognise. | ||
| + | - Check **Settings → Apps → Permission manager → SMS** and revoke SMS-read from every non-bank, non-OTP app. A fake app uses this to steal OTPs from the notification shade. | ||
| + | |||
| + | If money was lost, plan for a **factory reset** after the bank investigation closes (not before, because the forensic team or the cyber cell may need the evidence on the device). When you do reset, do **not** restore from the cloud backup until the cyber cell has confirmed it is clean. A poisoned backup will simply reinstall the fake app. | ||
| + | |||
| + | ==== Step 7: Lock the SIM and the phone number (1 minute) ==== | ||
| + | |||
| + | If the attacker had any window of access, assume they harvested your contacts, OTPs and SIM details. Visit a service-provider store within 24 hours and ask for an **SIM lock with a personal unlock key (PUK)**. Optional: trigger a **SIM swap with KYC re-verification** so any cloned SIM the attacker may have provisioned is killed. The full process is at [[sim-card-stopped-swap-kyc-recovery-india|recover a stopped or swapped SIM]]. | ||
| + | |||
| + | ===== The evidence checklist (before doing anything irreversible) ===== | ||
| + | |||
| + | The phone IS the evidence. Preserve these before any reset: | ||
| + | |||
| + | - **Install timestamp screenshots** from Settings → Apps → [suspicious app] → App info | ||
| + | - **Package name** (e.g. " | ||
| + | - **APK file** on disk (Downloads / Files app), copied to USB; do not open | ||
| + | - **WhatsApp / Telegram / SMS thread** from whoever sent the install link, with sender number | ||
| + | - **Call log entries** for any number that asked you to install AnyDesk / TeamViewer or read out an OTP | ||
| + | - **Bank debit SMS** with UTR / RRN visible | ||
| + | - **Net-banking login alerts**, even if no money moved | ||
| + | - **Photo of the home screen** showing the suspicious icon (or its absence after auto-hide) | ||
| + | - **Date and exact time** you noticed the fraud, written on paper | ||
| + | - **APK file hash** using any free tool | ||
| + | |||
| + | Email these to yourself as a single captioned PDF before any reset. Many victims lose their case at this step. | ||
| + | |||
| + | ===== The official complaint route ===== | ||
| + | |||
| + | The Indian system is multi-channel by design. File on the relevant channels in this order: | ||
| + | |||
| + | - **1930 helpline** within the golden hour for any financial loss. Details: [[1930-helpline-cyber-fraud-script|1930 helpline script]]. | ||
| + | - **NCRP portal** at https:// | ||
| + | - **Local police cyber cell** with FIR if the loss exceeds ₹50,000 or if identity theft has occurred. See "When cyber/ | ||
| + | - **Sanchar Saathi → Chakshu** at https:// | ||
| + | - **CERT-In Vulnerability Disclosure** at https:// | ||
| + | - **Google Play Protect report** if the app came from Play, via Play Store → app listing → three-dot menu → "Flag as inappropriate" | ||
| + | - **Apple App Store report** at https:// | ||
| + | - **Bank ombudsman** at https:// | ||
| + | - **DPDP Data Principal complaint** to the relevant Data Protection Board if a fake loan app misused contacts or photos (DPDP Act 2023, §13 grievance redressal). | ||
| + | |||
| + | The legal handles: | ||
| + | |||
| + | - **Information Technology Act 2000, §43**: civil compensation for unauthorised access | ||
| + | - **IT Act §66**: criminal penalty for the same | ||
| + | - **IT Act §66C**: identity theft (uses of password, electronic signature, unique ID) | ||
| + | - **IT Act §66D**: cheating by personation using a computer resource | ||
| + | - **IT Act §66E**: violation of privacy (covers the image-blackmail variant of fake loan apps) | ||
| + | - **Bharatiya Nyaya Sanhita 2023 §318**: cheating, the BNS section that replaced IPC §420 from 1 July 2024 | ||
| + | - **BNS §319**: cheating by personation, | ||
| + | - **BNS §336**: forgery of electronic record | ||
| + | - **Bharatiya Nagarik Suraksha Sanhita 2023 §173**: registration of FIR for cognisable offences | ||
| + | - **RBI Digital Lending Guidelines 2022** for fake-loan-app cases: only entities listed in the RBI app-registry can lend; any other app is illegal on its face | ||
| + | - **DPDP Act 2023 §17 and §18**: penalties for processing personal data without consent | ||
| + | |||
| + | ===== When cyber cell or police involvement is essential ===== | ||
| + | |||
| + | You should always file the NCRP complaint. You **additionally** need an FIR at a police station or cyber-crime cell when any of these is true: | ||
| + | |||
| + | - The loss is **₹50,000 or above** | ||
| + | - You have evidence of **identity theft** (Aadhaar / PAN / driving licence misuse, not just a card debit) | ||
| + | - The fake app is a **loan-app with extortion or morphed-image blackmail**, | ||
| + | - The bank refuses to act, an FIR forces the bank's hand | ||
| + | - Multiple people in your family or housing-society WhatsApp group were hit with the same APK, this is a **chargeable conspiracy** | ||
| + | - **Children or senior citizens** were the targets, special-category offences attract higher punishment under BNS §111 (organised crime) and §112 (petty organised crime) when the modus is repeated | ||
| + | |||
| + | Go to the cyber-crime station nearest you, not the one nearest the fraudster, jurisdiction is now decided by the victim' | ||
| + | |||
| + | If the cyber cell refuses to register the FIR, file an RTI on the police station seeking the **General Diary entry** and the **station-house officer' | ||
| + | |||
| + | ===== Sample bank-alert email ===== | ||
| + | |||
| + | Copy this template into your email, fill the bracketed fields, send to the bank's grievance address (printed inside the bank app under " | ||
| + | |||
| + | < | ||
| + | To: grievance@[yourbank].co.in | ||
| + | Cc: nodalofficer@[yourbank].co.in | ||
| + | Subject: URGENT: Fraud-suspect app installed on registered mobile - freeze all channels - account ending [last 4 digits] | ||
| + | |||
| + | Sir/Madam, | ||
| + | |||
| + | I am the registered account holder of savings/ | ||
| + | |||
| + | I have placed the device on airplane mode and uninstalled the app via Safe Mode. I have not yet performed a factory reset, as I am preserving the device as evidence. | ||
| + | |||
| + | I request the bank, under the Master Direction on Digital Payment Security Controls 2021 and the customer-protection circular DBR.No.Leg.BC.78/ | ||
| + | |||
| + | 1. Immediately freeze all debit and credit cards on the account | ||
| + | 2. Disable UPI on all VPAs linked to this account | ||
| + | 3. Disable internet banking and mobile banking access pending in-branch verification | ||
| + | 4. Block OTP delivery on the registered mobile number for the next 72 hours | ||
| + | 5. Apply a hold on any pending high-value transactions in the last 24 hours | ||
| + | 6. Acknowledge this email within 24 hours with a complaint reference number | ||
| + | |||
| + | The relevant cybercrime complaint number is [NCRP ack number] and the 1930 call reference is [1930 reference]. I have also filed the suspicious-communication report on Sanchar Saathi / Chakshu (reference [Chakshu ref]). | ||
| + | |||
| + | If money has been debited, I am invoking the zero-liability framework. The breach falls within " | ||
| + | |||
| + | Please confirm in writing the actions taken and the timeline. | ||
| + | |||
| + | Yours faithfully, | ||
| + | [Full name] | ||
| + | [Account holder] | ||
| + | [Date] | ||
| + | [Place] | ||
| + | </ | ||
| + | |||
| + | Send a copy to your own personal email and save the read-receipt. If the bank does not respond within 24 hours, forward the same email to the bank's **Principal Nodal Officer** (address is on the bank website under " | ||
| + | |||
| + | For the full bank-freeze legal mechanics, see [[bank-freeze-cyber-fraud-india|the bank-freeze process]] and [[golden-hour-zero-liability-cyber-fraud-rbi-india|the golden-hour zero-liability rule]]. If a lien has already been placed on your account because you were the **receiving** end of a separate fraud, the page [[lien-amount-bank-account-removal|how to get a bank lien removed]] explains the unfreeze route. The acknowledgement-decoding helper sits at [[ncrp-acknowledgement-bank-lien-decoder-india|NCRP acknowledgement and bank-lien decoder]]. | ||
| + | |||
| + | ===== Common mistakes that turn a recoverable case into a lost case ===== | ||
| + | |||
| + | - **Factory-resetting before evidence capture.** The phone is the only artefact a forensic lab can examine. Reset only after the bank or cyber cell green-lights it. | ||
| + | - **Replying to the fraudster** to "tell them off", this confirms the number is live and you are the right person. | ||
| + | - **Reinstalling the same app to "check what it does" | ||
| + | - **Trusting a " | ||
| + | - **Using the infected phone for netbanking from the browser.** The device is compromised. Use a clean device. | ||
| + | - **Restoring an old backup without checking install dates.** A backup taken after the install contains the fake app. Pick a backup from before. | ||
| + | - **Skipping the NCRP filing because "no money moved" | ||
| + | - **Calling the number that "the fraudster' | ||
| + | - **Paying a fake " | ||
| + | - **Ignoring the SIM.** The attacker can clone your number and start step two. Always do step 7. | ||
| + | |||
| + | ===== Real-life example ===== | ||
| + | |||
| + | <WRAP center round box> | ||
| + | **Case study: Pune homemaker, March 2026.** A 54-year-old in Pune received a WhatsApp APK titled " | ||
| + | </ | ||
| + | |||
| + | The two takeaways: speed in the first hour, and refusal to factory-reset before evidence capture. | ||
| + | |||
| + | ===== Permissions you should never grant to a non-government, | ||
| + | |||
| + | If an app asks for any two of these on first launch, treat it as malicious until proven otherwise: **accessibility service**, **display over other apps**, **SMS read and send**, **notification access**, **device admin**, **install unknown apps**, **contacts and call logs**, **all-files storage access**, or **run in background / ignore battery optimisation**. A legitimate bank app asks for exactly one (SMS, for OTP autofill) and says so upfront. Government apps like DigiLocker, mParivahan or IRCTC will not ask for accessibility or display-over-other-apps. The deep dive on each permission is at [[app-permissions-camera-contacts-sms-location-india|app permissions: | ||
| + | |||
| + | ===== If the fraud included an OAuth or social-login hijack ===== | ||
| + | |||
| + | If you tapped "Sign in with Google" | ||
| + | |||
| + | ===== Frequently asked questions ===== | ||
| + | |||
| + | ==== Q1: I deleted the app the moment I realised. Am I safe now? ==== | ||
| + | |||
| + | Probably not. Many fake apps install a second-stage payload that survives the visible app's uninstall, especially on rooted Android or on phones with **install unknown apps** turned on. Run Play Protect and confirm with a Safe Mode reboot that no unfamiliar app remains. If money moved at any point, still file the NCRP complaint, the digital trail does not vanish when the icon vanishes. | ||
| + | |||
| + | ==== Q2: Is the airplane-mode step really necessary if the app is not opened? ==== | ||
| + | |||
| + | Yes. Many fake apps run a background service the moment they are installed, especially those with **accept install permissions** flagged. They will exfiltrate contacts, SMS history and stored photos without ever showing a UI. Airplane mode is the only one-tap kill switch you have. | ||
| + | |||
| + | ==== Q3: Should I factory-reset the phone immediately to be safe? ==== | ||
| + | |||
| + | Not until the bank acknowledges your freeze in writing and either the cyber cell has copied the evidence off the device or has formally said they do not need it. The phone is your single best piece of evidence. Reset destroys it. After clearance, do reset, and choose "Set up as new" not " | ||
| + | |||
| + | ==== Q4: I installed an " | ||
| + | |||
| + | Yes. No bank, anywhere, ever asks you to install AnyDesk, TeamViewer, QuickSupport or any remote-control app to verify anything. This is one of the single most common modus operandi flagged by RBI's " | ||
| + | |||
| + | ==== Q5: The fake app threatened to send my photos to my contacts. What now? ==== | ||
| + | |||
| + | This is the fake-loan-app blackmail pattern, covered by BNS §308 (extortion), | ||
| + | |||
| + | ==== Q6: Will my bank refund me automatically under zero-liability? | ||
| + | |||
| + | Not automatically. The Reserve Bank's zero-liability framework requires the customer to notify the bank within three working days of the unauthorised transaction. If you do, and the breach is found to be a third-party breach where neither bank nor customer was negligent, the customer' | ||
| + | |||
| + | ==== Q7: My phone is an iPhone. Do I still need to worry about fake apps? ==== | ||
| + | |||
| + | You need to worry about fake configuration profiles, fake "Sign in with Apple" prompts inside web pages, fake App Store listings (Apple has removed thousands of fake bank apps but a few slip in), and fake TestFlight builds shared by link. iOS does not allow sideloading APKs the way Android does, but a malicious Safari profile or a phished Apple ID gives the attacker enough leverage. Steps 0, 2, 4, 5 of the plan apply identically. The iOS-specific cleanup is in step 2 (remove unknown configuration profile under Settings → General → VPN & Device Management). | ||
| + | |||
| + | ==== Q8: I cannot remember which app I installed. The phone "feels weird" but nothing in Settings looks new. ==== | ||
| + | |||
| + | Sort the app list by **install date** (Settings → Apps → Sort → "First installed" | ||
| + | |||
| + | ==== Q9: The fake app asked me to read out an OTP "to cancel" | ||
| + | |||
| + | The bank will argue that reading out an OTP is a customer-side breach, which moves you from zero-liability to limited-liability. The counter-argument: | ||
| + | |||
| + | ==== Q10: How do I make sure this never happens again? ==== | ||
| + | |||
| + | Five permanent settings on the affected phone, applied once, hold for years: turn off **Install unknown apps** for every source under Settings → Security; keep **Play Protect** enabled and scheduled; review **Accessibility services** monthly and leave only the apps that genuinely need it (TalkBack, password managers); review **Notification access** every quarter; and inside your bank app, enable per-day and per-beneficiary **transaction limits** so any single fraud is capped. Tell every family member about steps 0 through 7. The single biggest predictor of "Will this person get caught" | ||
| + | |||
| + | ===== FAQ schema note ===== | ||
| + | |||
| + | The site's auto-schema layer (`/ | ||
| + | |||
| + | ===== Sources and further reading ===== | ||
| + | |||
| + | - **CERT-In Cyber Security Advisories**, | ||
| + | - **Indian Cybercrime Coordination Centre (I4C) NCRP portal**, https:// | ||
| + | - **1930 helpline**, 24x7 National Cyber Crime Helpline | ||
| + | - **Sanchar Saathi (Chakshu)**, | ||
| + | - **Reserve Bank of India Master Direction on Digital Payment Security Controls 2021** | ||
| + | - **RBI Customer Protection Circular DBR.No.Leg.BC.78/ | ||
| + | - **RBI Guidelines on Digital Lending 2022**, https:// | ||
| + | - **Google Play Protect documentation**, | ||
| + | - **Apple App Store Review Guidelines**, | ||
| + | - **Information Technology Act 2000**, with §43, §66, §66C, §66D, §66E | ||
| + | - **Bharatiya Nyaya Sanhita 2023**, §318 (cheating), §319 (cheating by personation), | ||
| + | - **Bharatiya Nagarik Suraksha Sanhita 2023**, §173 (FIR for cognisable offences) | ||
| + | - **Digital Personal Data Protection Act 2023**, §13 grievance redressal, §17, §18 penalties | ||
| + | - **RBI Integrated Ombudsman Scheme 2021**, https:// | ||
| + | |||
| + | ===== Related citizen guides on RTI Wiki ===== | ||
| + | |||
| + | - [[1930-helpline-cyber-fraud-script|1930 cyber fraud helpline: the exact 7-minute script]] | ||
| + | - [[golden-hour-zero-liability-cyber-fraud-rbi-india|Golden-hour zero-liability rule explained]] | ||
| + | - [[bank-freeze-cyber-fraud-india|How a bank freezes a fraud beneficiary account]] | ||
| + | - [[lien-amount-bank-account-removal|Bank lien on your account: how to get it removed]] | ||
| + | - [[ncrp-acknowledgement-bank-lien-decoder-india|Decoding the NCRP acknowledgement and the bank-lien notice]] | ||
| + | - [[sim-card-stopped-swap-kyc-recovery-india|SIM card stopped or swapped: KYC recovery walkthrough]] | ||
| + | - [[app-permissions-camera-contacts-sms-location-india|App permissions explained: camera, contacts, SMS, location]] | ||
| + | - [[account-locked-google-apple-meta-microsoft-recovery-india|Account locked on Google, Apple, Meta or Microsoft: recovery routes]] | ||
| + | - [[citizen-rti-playbook|The citizen RTI playbook]] | ||
| + | |||
| + | ===== Hero image prompt ===== | ||
| + | |||
| + | < | ||
| + | Editorial illustration, | ||
| + | </ | ||
| + | |||
| + | ---- | ||
| + | |||
| + | This guide is published by the RTI Wiki editorial team for general public education. It is not legal advice. For your specific situation, consult a qualified lawyer or a registered cyber-crime cell. | ||
| + | |||
| + | {{tag> | ||