Overview:
A rogue APK was circulating on Telegram and shady download sites, mimicking a SEBI-registered share broker’s official trading app. The fake app captured investor logins and redirected them to scam investment schemes.
ThreatWatch360 in Action:
-
Identified the rogue app during routine dark web and open-source scans.
-
Conducted a quick reverse-engineering to map scam infrastructure.
-
Coordinated app takedown with hosting providers and CERT-In.
-
Alerted investors via the broker’s official channels.
Results:
✅ App removed within 72 hours.
✅ 1,200 investors were warned before they downloaded the fake app.
✅ Broker avoided SEBI penalties for customer data mishandling.


