Telangana cyber bureau warns of WhatsApp takeover scam spreading via fake apps

HYDERABAD: Telangana Cyber Security Bureau (TGCSB) has issued a public advisory warning users against a new wave of WhatsApp takeover scams being spread through malicious application links shared on the messaging platform. The bureau said fraudsters are disguising these links as official messages from banks, courier services, or government agencies.
According to the advisory, cybercriminals are circulating Android Package Kit (APK) files on WhatsApp under the guise of “RTA challan,” “bank KYC update,” “customer care,” or “courier invoice” apps. Once installed, the app gains access to the victim’s contacts and text messages, including one-time passwords. “The attacker then uses the OTP to re-register the victim’s WhatsApp account on another device, effectively taking control,” the TGCSB said.
iPhone users also being targeted
The bureau noted that even iPhone users are being duped through call-forwarding codes. “Fraudsters convince victims to dial codes such as **21*number#, which redirect calls and messages to the attacker’s number. This enables them to hijack the WhatsApp account,” the advisory warned.
Steps for immediate recovery
Users who suspect infection are advised to disable call forwarding, uninstall unknown apps, and perform a factory reset. The bureau recommended reinstalling WhatsApp only from verified sources like Google Play Store or Apple App Store. Victims locked out of their accounts can recover access by visiting www.whatsapp.com/contact.
To identify malicious or hidden apps, TGCSB suggested using the government’s M-Kavach 2 security app. The advisory further urged citizens never to install APK files shared over WhatsApp or SMS and to avoid following instructions to dial numbers containing special characters.
Report fraud immediately
The public has been urged to report financial loss cases by dialling the 1930 cyber fraud helpline or filing complaints on www.cybercrime.gov.in.
“Enable two-step verification in WhatsApp and remain vigilant against unsolicited messages or app links,” said Shikha Goel, IPS, Director, TGCSB.


