How to safeguard your UPI account from latest ‘Digital Lutera’ malware

In today’s digital age, it has become essential to stay careful of banking-related scams to avoid getting into a financial crisis. Not to forget, with the ease of UPI, even scammers have started to target the platform so that users can send money. Just recently, it was reported that a new type of scam has spread in the market, known as the ‘Digital Lutera’ scam. Rather than scammers calling or texting you to ask for money, this scam involves getting access to your Android device directly and then using it to take out money using the UPI account. Let’s take a deep dive into how this scam works and how you can safeguard yourself from such scams.

Digit.in

Digit.in

Survey

✅ Thank you for completing the survey!
${q.options.map(opt => ` `).join(“”)}

`; // trigger animation const inner = qaContainer.querySelector(“.qa-inner”); setTimeout( => inner.classList.add(“show”), 50); document.querySelectorAll(“input[name=’answer’]”).forEach(radio => { radio.addEventListener(“change”, => submitAnswer(radio.value)); });}function showThankYou { thankYouBox.style.display=”block”; setTimeout( => thankYouBox.classList.add(“show”), 50);}function submitAnswer(answerValue) { const finalPayload = { campaign_name: “Digit Questionaire”, form_name: “Digit Questionaire_Form 1”, form_data: [ { key: “uuid”, value: deviceId, type: “text” }, { key: “question”, value: questions[currentQuestionIndex].question, type: “text” }, { key: “response”, value: answerValue, type: “text” } ], verification_data: { captcha_verification: “”, captchaValue: null, captchaId: null, phone_verification: false, email_verification: false }, meta_data: { referer: document.referrer || window.location.href, user_agent: getDeviceType } }; const myHeaders = new Headers ; myHeaders.append(“accept”, “*/*”); myHeaders.append(“origin”, “https://www.timesdrive.in”); myHeaders.append(“user-agent”, navigator.userAgent); const formdata = new FormData ; formdata.append(“finalPayload”, JSON.stringify(finalPayload)); fetch(“https://apivelocitynext.tnn.in/submit-form-data/68b6d8aac3aa7094b919ac4f/68b6d8f5c3aa7094b919ac89”, { method: “POST”, headers: myHeaders, body: formdata }) .then(res => res.text ) .then(result => console.log(“Submitted:”)) .catch(err => console.error(“Error:”)); currentQuestionIndex++; progress++; setCookie(“progress”, progress); if (currentQuestionIndex { qaBox.style.display=”none”; showThankYou ; }, 600); }}if (currentIndex qaBox.classList.add(“show”), 1200); showQuestion(currentIndex);}

NASA satellite to crash land on Earth after 14 years: Full story in 5 points

How does the ‘Digital Lutera’ malware work?

What is Necro Trojan? The new malware that spreads via Google Play Store and has already affected over 11 mn devices

First reported by Gadgets360, the Digital Lutera malware is not like the traditional scams, which involve scammers asking for money over the phone or by sending you links in the form of SMS messages. Scammers have found a new way; they rely on changing your Android phone’s behaviour rather than trying to directly get into the UPI payment app.

It is a fraud toolkit that can bypass digital payment systems using UPI-linked bank accounts and SMS-based OTP verification. Experts reported that this scam takes place in the form of APKs. It begins when the user installs an APK file that they might have got over the internet or from some other sources. These apps are injected with a Trojan, and as soon as they are installed, the apps request permissions for reading and writing SMS.

If the permissions are granted, then the ‘Digital Lutera’ malware starts its process, and it runs silently in the background. It looks at the incoming bank verification messages with the help of a different set of modules. And using that, the attacker tries to log in to the victim’s account through a modified version of the app on their own device.

UPDATE: The NPCI (National Payments Corporation of India) has officially given out a statement on this matter.

They said, “This is in reference to recent media reports citing a report on certain fraud-related modus operandi using latest technology to bypass UPI device binding. NPCI has examined the report and clarifies that robust checks and safeguards are already in place to address such risks.”

Furthermore, adding, “UPI is designed with multiple layers of security and authentication mechanisms to ensure that transactions remain safe and secure. NPCI continues to work closely with banks and ecosystem partners to monitor risks and strengthen security measures, ensuring that digital payments remain safe and reliable for users.”

Still, here are the best practices or tips to follow for your safety.

How to safeguard yourself from such scams

Speaking of how you can actually save yourself from such scams, there are a few basic steps that you can follow to save yourself. Follow some of the safeguard techniques and methods mentioned below:

  • Make sure not to install any apps outside of official app stores like the Google Play Store.
  • Avoid any text messages that ask you to install any sort of APKs, in the form of a traffic challan, or maybe even an invitation to an event.
  • Make sure Google Play Protect on your phone is active and updated to the latest version.
  • If you’re downloading any third-party APKs, make sure they don’t get flagged by Google Play Protect; if they do, avoid installing those files.
  • Update your phone’s software to the latest version, which includes the latest security patch.

While these steps can help reduce the risk of falling victim to such malware, they do not guarantee complete protection. Scammers are constantly finding new ways to exploit digital systems, which makes it important for users to stay alert. The safest approach is to be mindful about what you install on your phone and where those apps come from.

As mentioned, avoid downloading unknown APK files, be cautious with links or attachments you receive, and regularly check the permissions granted to apps on your device. A little caution while installing apps and managing your phone’s security settings can go a long way in keeping your UPI account and personal data safe.

Google unveils Gemini Embedding 2, its first multimodal embedding model

Latest

IPhone 18 Pro Dynamic Island leak hints at big changes from Apple, here is all you need to know

iPhone 18 Pro and iPhone 18 Pro Max may come with a smaller Dynamic Island cutout. Here is what we know so far.

Study says AI has yet to transform cybercrime

Study says AI has yet to transform cybercrime

Google Chrome is secretly downloading 4GB AI model on some laptops, here is what you can do about it

Researcher Alexander Hanff says Google Chrome is downloading a roughly 4GB Gemini Nano model onto some eligible devices without a clear user prompt. The claim h

Vivo X300 FE with Snapdragon 8 Gen 5 processor, 6,500mAh battery launched in India: Price, specs and features

Vivo has unveiled the X300 Fan Edition featuring ZEISS optics, Snapdragon 8 Gen 5, and a 6.31-inch AMOLED display. It offers a 6,500mAh battery, advanced camera

CMF Watch 3 Pro launched with AMOLED display and 13-day battery life, price is Rs 7,999

Nothing’s spin-off brand CMF has launched the Watch 3 Pro in India. The wearable succeeds the Watch 2 Pro that was released 2 years ago. The Watch 3 Pro bring

Topics

WB Madhyamik Result 2026: How to check West Bengal 10th result via SMS, mobile app

WBBSE will announce the Madhyamik Result 2026 tomorrow after an official press conference at 9:30 am. Students can access their Class 10 scorecards online throu

Why were 3.4% of CUET UG candidates allotted alternate exam cities? NTA explains

The NTA has opened a reallocation window after some CUET UG 2026 candidates were allotted centres outside their chosen cities. The move follows complaints over

HQ-29 vs S-500: China turns its missile shield towards India – Will New Delhi buy Russia’s S-500?

Reports suggest that Beijing has deployed the HQ-29 system near the border. Videos circulating on Chinese social media show defence equipment being transported

Canada’s Carbon Tax Hinders Pipeline Plans, Cenovus CEO Says

Alberta’s planned oil pipeline to the west coast requires Canada to shift away from stricter climate policies and toward promoting greater oil production from

Marandi Says US Sought Ceasefire After Battlefield Failure In Iran

In an exclusive interview in Tehran, Professor Seyed Mohammad Marandi said Iran holds the upper hand in the confrontation with the United States. He portrayed W

Income-tax returns: Received a tax notice from the I-T department? Here’s what you should do — Stepwise guide

Filing income-tax returns online has become easier, but first-time taxpayers may find it confusing. Income Tax notices can be issued for various reasons, here's

US disables Iranian-flagged tanker breaching blockade in Gulf of Oman

Earlier today, Axios reports indicated the U.S. and Iran are closing in on a potential one-page framework agreement that could formally end hostilities.

Hantavirus outbreak due to Dutch couple’s birdwatching tour? What officials said

Health officials are tracing whether the MV Hondius hantavirus outbreak began with rodent exposure in Argentina or rare close contact on board. The inquiry has
spot_img

Related Articles

Popular Categories

spot_imgspot_img