Hackers create fake IRCTC app and website: warning issued for all Android users

Highlights
  • IRCTC  has issued a warning for all Android smartphone users. 
  • The advisory says to stay away from downloading a specific malicious file.
  • As per IRCTC, downloading that file may help scammers steal your personal data.

In a bid to keep its users safe from scams, the Indian Railway Catering and Tourism Corporation (IRCTC) has issued a new ‘warning’ message for all Android users. In the new advisory, IRCTC refrains Android users from downloading a malicious file, named “irctcconnect.apk,” as doing so might help scammers steal your personal data. The malicious file is shared through instant messaging apps like WhatsApp and Telegram. It also hosts a fake website at https://irctc.creditmobile.site.

Show Full Article

IRCTC warning for Android smartphone users

According to IRCTC, if you download this malicious file, it will install malware on your phone, which can potentially steal your data. A phishing website is being hosted at https://irctc.creditmobile.site. The website appears to be identical to the official IRCTC website, but if you enter any personal information, scammers may gain access to your credentials and potentially misuse them.

“This Android app (APK file) is malicious and infects the mobile device,” IRCTC said.

IRCTC stated that these fraudsters are impersonating IRCTC officials and urging users to download an Android application. The intention is to deceive victims into revealing their sensitive net banking credentials, such as UPI details and credit/debit card information.

How to stay safe from this IRCTC scam?

IRCTC has issued a strict warning to its users against downloading fake or phishing apps. If you enter your personal information, there is a risk of losing a significant amount of money from your bank account. It is crucial to protect oneself from such fraudulent activities. To ensure safety, it is recommended that the IRCTC app be downloaded from either the Google Play Store or the Apple App Store.

It is important to mention that IRCTC will never request users to disclose their personal identification number (PIN), credit card number, one-time password (OTP), bank account number, or UPI over the phone.