How to safeguard your UPI account from latest ‘Digital Lutera’ malware

In today’s digital age, it has become essential to stay careful of banking-related scams to avoid getting into a financial crisis. Not to forget, with the ease of UPI, even scammers have started to target the platform so that users can send money. Just recently, it was reported that a new type of scam has spread in the market, known as the ‘Digital Lutera’ scam. Rather than scammers calling or texting you to ask for money, this scam involves getting access to your Android device directly and then using it to take out money using the UPI account. Let’s take a deep dive into how this scam works and how you can safeguard yourself from such scams.

Digit.in

Digit.in

Survey

✅ Thank you for completing the survey!
${q.options.map(opt => ` `).join(“”)}

`; // trigger animation const inner = qaContainer.querySelector(“.qa-inner”); setTimeout( => inner.classList.add(“show”), 50); document.querySelectorAll(“input[name=’answer’]”).forEach(radio => { radio.addEventListener(“change”, => submitAnswer(radio.value)); });}function showThankYou { thankYouBox.style.display=”block”; setTimeout( => thankYouBox.classList.add(“show”), 50);}function submitAnswer(answerValue) { const finalPayload = { campaign_name: “Digit Questionaire”, form_name: “Digit Questionaire_Form 1”, form_data: [ { key: “uuid”, value: deviceId, type: “text” }, { key: “question”, value: questions[currentQuestionIndex].question, type: “text” }, { key: “response”, value: answerValue, type: “text” } ], verification_data: { captcha_verification: “”, captchaValue: null, captchaId: null, phone_verification: false, email_verification: false }, meta_data: { referer: document.referrer || window.location.href, user_agent: getDeviceType } }; const myHeaders = new Headers ; myHeaders.append(“accept”, “*/*”); myHeaders.append(“origin”, “https://www.timesdrive.in”); myHeaders.append(“user-agent”, navigator.userAgent); const formdata = new FormData ; formdata.append(“finalPayload”, JSON.stringify(finalPayload)); fetch(“https://apivelocitynext.tnn.in/submit-form-data/68b6d8aac3aa7094b919ac4f/68b6d8f5c3aa7094b919ac89”, { method: “POST”, headers: myHeaders, body: formdata }) .then(res => res.text ) .then(result => console.log(“Submitted:”)) .catch(err => console.error(“Error:”)); currentQuestionIndex++; progress++; setCookie(“progress”, progress); if (currentQuestionIndex { qaBox.style.display=”none”; showThankYou ; }, 600); }}if (currentIndex qaBox.classList.add(“show”), 1200); showQuestion(currentIndex);}

NASA satellite to crash land on Earth after 14 years: Full story in 5 points

How does the ‘Digital Lutera’ malware work?

What is Necro Trojan? The new malware that spreads via Google Play Store and has already affected over 11 mn devices

First reported by Gadgets360, the Digital Lutera malware is not like the traditional scams, which involve scammers asking for money over the phone or by sending you links in the form of SMS messages. Scammers have found a new way; they rely on changing your Android phone’s behaviour rather than trying to directly get into the UPI payment app.

It is a fraud toolkit that can bypass digital payment systems using UPI-linked bank accounts and SMS-based OTP verification. Experts reported that this scam takes place in the form of APKs. It begins when the user installs an APK file that they might have got over the internet or from some other sources. These apps are injected with a Trojan, and as soon as they are installed, the apps request permissions for reading and writing SMS.

If the permissions are granted, then the ‘Digital Lutera’ malware starts its process, and it runs silently in the background. It looks at the incoming bank verification messages with the help of a different set of modules. And using that, the attacker tries to log in to the victim’s account through a modified version of the app on their own device.

UPDATE: The NPCI (National Payments Corporation of India) has officially given out a statement on this matter.

They said, “This is in reference to recent media reports citing a report on certain fraud-related modus operandi using latest technology to bypass UPI device binding. NPCI has examined the report and clarifies that robust checks and safeguards are already in place to address such risks.”

Furthermore, adding, “UPI is designed with multiple layers of security and authentication mechanisms to ensure that transactions remain safe and secure. NPCI continues to work closely with banks and ecosystem partners to monitor risks and strengthen security measures, ensuring that digital payments remain safe and reliable for users.”

Still, here are the best practices or tips to follow for your safety.

How to safeguard yourself from such scams

Speaking of how you can actually save yourself from such scams, there are a few basic steps that you can follow to save yourself. Follow some of the safeguard techniques and methods mentioned below:

  • Make sure not to install any apps outside of official app stores like the Google Play Store.
  • Avoid any text messages that ask you to install any sort of APKs, in the form of a traffic challan, or maybe even an invitation to an event.
  • Make sure Google Play Protect on your phone is active and updated to the latest version.
  • If you’re downloading any third-party APKs, make sure they don’t get flagged by Google Play Protect; if they do, avoid installing those files.
  • Update your phone’s software to the latest version, which includes the latest security patch.

While these steps can help reduce the risk of falling victim to such malware, they do not guarantee complete protection. Scammers are constantly finding new ways to exploit digital systems, which makes it important for users to stay alert. The safest approach is to be mindful about what you install on your phone and where those apps come from.

As mentioned, avoid downloading unknown APK files, be cautious with links or attachments you receive, and regularly check the permissions granted to apps on your device. A little caution while installing apps and managing your phone’s security settings can go a long way in keeping your UPI account and personal data safe.

Google unveils Gemini Embedding 2, its first multimodal embedding model

Latest

Motorola Edge 50 Ultra price drops by over Rs 15,000 on Flipkart: Here’s the deal

Motorola Edge 50 Ultra gets a Rs 15,000 discount on Flipkart, bringing the price to Rs 49,999. Buyers can also avail bank offers and exchange deals.

Maamla Legal Hai Season 2: OTT release date, platform, storyline, cast and more

Maamla Legal Hai Season 2 releases on April 3 on Netflix with Ravi Kishan returning as V.D. Tyagi and new courtroom comedy cases in Patparganj.

NASA satellite to crash land on Earth after 14 years: Full story in 5 points

NASA’s 14-year-old Van Allen Probe A satellite is making an uncontrolled re-entry to Earth. Experts say most parts will burn up in the atmosphere.

Intel announces Core Ultra 200S Plus desktop processors

Intel's Core Ultra 200S Plus desktop CPUs boost gaming/multithreaded performance. Features up to 24 cores & faster DDR5 support.

Google unveils Gemini Embedding 2, its first multimodal embedding model

Google introduces Gemini Embedding 2, its first multimodal embedding model designed to map text, images, audio, and video into a single space.

Topics

Flipperachi, rapper behind Dhurandhar’s viral track FA9LA, cancels India performance amid Middle East tensions

Flipperachi, the Bahraini rapper who gained popularity in India after his track FA9LA featured in the spy thriller Dhurandhar, will no longer be perfo.

Daniel Jones signs record-breaking 2-year, $88M deal with Indianapolis Colts

Daniel Jones joined the Indianapolis Colts ahead of the 2025 campaign and quickly proved his value. The deal's structure, with heavy guarantees and record-setti

US responsible for strike on Iranian girls’ school that killed 175, probe finds targeting mistake

New York Times report which cited unnamed US officials familiar with the findings says the strike on February 28 hit the Shajarah Tayyebeh elementary school, ki

IPL 2026 schedule: 3 matches to look forward to from the first 20 fixtures of season

The much-awaited schedule of the 19th edition of the Indian Premier League (IPL) was announced today, albeit only for the first two weeks. However, even these f

Iran rejects 2026 FIFA World Cup participation: Sports minister cites Khamenei assassination and US host role as reasons

Iran sports minister, Ahmad Donyamali pointed directly to the US-led actions that resulted in the death of Supreme Leader Ayatollah Ali Khamenei.

Hansika Motwani-Sohael Khaturiya’s divorce, Thakkali Srinivasan’s demise, Harish Shankar’s apology to Mahesh Babu fans: Top 5 South stories of the day

There has been a lot happening in the South Indian film industry today, with several developments making headlines. From emotional announcements and o.

Trey Hendrickson trade: Baltimore Ravens land pass rusher on 4-year, $112 million deal

Baltimore Ravens' pass rush struggled last season with just 30 sacks, one of the lowest totals in franchise history. Trey Hendrickson, a four-time Pro Bowler an

IEA announces release of 400 million oil barrels from emergency reserves amid Iran war | What it means

The International Energy Agency has agreed to release 400 million barrels of oil from emergency reserves to stabilise markets amid tensions in the Middle East l
spot_img

Related Articles

Popular Categories

spot_imgspot_img