Digital Lutera Android Toolkit Hijacks UPI Accounts, NPCI Responds
Digital Lutera Android Toolkit Hijacks UPI Accounts, NPCI Responds
The government has pressed ahead with a SIM-binding mandate for messaging and financial platforms, saying the move connects services like messaging apps and UPI platforms to the user’s primary device. DoT officials describe the policy as a step to curb digital fraud and identity misuse, though researchers have now identified a toolkit that targets Android at the system level to bypass these protections.
Cybersecurity firm CloudSEK has identified a fraud toolkit named Digital Lutera that can bypass the SIM-based verification mechanism used for digital payment services in India. CloudSEK says the toolkit manipulates Android system behavior through LSPosed, a framework that allows injection of custom modules into the Android runtime. By intercepting incoming SMS messages and spoofing authorization signals, Digital Lutera aims to gain access to a victim’s UPI-linked accounts. The toolkit is reportedly spread via Telegram groups, with researchers spotting more than 20 groups and multiple members across them.
CloudSEK says the attack proceeds in phases that center on altering the Android platform rather than breaking into a banking app. Victims are lured into installing a malicious Android application, often disguised as a harmless file such as a traffic challan notice or a wedding invitation. Trojanised applications are requesting to be able to read/write SMS and run in the background, where verification messages (SMS) will then be sent to the attacker through the LSPosed modules. By being able to access the OTPs (One-Time Passwords), the attacker will then be able to log into a modified version of the same app on their device and trigger actions that will utilise the victim’s session.
Once a service sends an OTP to the victim’s phone number for login, the Trojan forwards the OTP to the attacker. The app then generates a device binding token, a credential used by banks to verify device legitimacy. The report notes that because the message appears to originate from the victim’s SIM card, telecom networks treat it as legitimate. With the device bound, the attacker can request a UPI PIN reset and gain control of the victim’s payment account to perform unauthorized transactions.
Researchers emphasize that many financial systems rely on the mobile number provided by telecom networks as proof of device ownership, leaving victims unaware that their UPI account has been accessed on another device while the attack runs quietly in the background.
CloudSEK says it responsibly disclosed its findings to financial institutions and authorities before publication to help with mitigation strategies.
NPCI answered the findings from the CloudSEK report, emphasising that UPI has been specifically designed using multiple levels of authentication and safeguards to provide assurance for safe transactions. They further stated that they are continuing to work with banks and the partner ecosystem to monitor risk and develop additional safeguards for customers' digital payments.
Update (March 11, 4:20pm): This article has been updated to reflect a statement from NPCI in response to CloudSEK’s report, and the headline has been updated accordingly.
The DoT’s SIM-binding policy is part of ongoing efforts to curb fraud and identity misuse in the digital payments ecosystem, officials say, with regulators watching evolving threat models as researchers publish new findings.