Mobile malware / WhatsApp

The Malicious APK Sent Over WhatsApp

This is currently the highest-volume consumer attack in Indonesia. An Android install file arrives through WhatsApp disguised as an ordinary document, and installing it gives an attacker the SMS and notification access needed to intercept one-time passcodes.

How the scam runs

A message arrives from an unknown number, or from a contact whose account has been taken over. Attached is a file ending in .apk, presented as something routine: a wedding invitation, a delivery receipt, a tax document, a bank statement, or a summons. The message is usually short and pushes for a quick look.

Because Android allows installation from outside the Play Store, tapping the file offers to install an app. The app requests permission to read SMS and notifications, often framed as needed to display the document. Once granted, the attacker can read every one-time passcode that arrives on the device.

With OTP interception in place, the attacker moves on the victim's accounts: mobile banking, e-wallets, and any service that authenticates by SMS code. The victim often notices nothing until money is gone, because the fraudulent transaction confirmations are being suppressed or read remotely.

Signals that give it away

The attachment ends in .apk

A genuine invitation, receipt or government notice is never an Android install file. Legitimate documents arrive as PDF, JPG or a link to a website. An .apk is an application, and no document needs to be an application.

The app asks to read SMS or notifications

There is no legitimate reason for an invitation viewer or receipt viewer to read your messages. This permission exists in the attack for exactly one purpose: intercepting authentication codes.

The sender is an unknown number, or a known contact behaving oddly

Attackers spread these files through compromised accounts, so the sender being someone you know is not reassurance. A contact who suddenly sends an unexpected file and pushes you to open it may not be in control of their account.

The message creates a reason to hurry

Wording about a package that will be returned, a fine that is about to escalate, or an event happening imminently is there to stop you examining the file. Urgency is the delivery mechanism, not a detail.

The one rule that stops it

Never install an application to view a document. If a file ending in .apk arrives from anyone, through any channel, do not open it. Verify by contacting the sender through a number you already had, not by replying to the message.

These pages describe fraud tactics for defensive awareness and staff briefing purposes. They are general information, not legal or financial advice. If you have lost money, report it through official channels: the police cyber crime unit, your bank, and for investment or lending matters, OJK.

Frequently asked questions

  • An .apk is the installer format for Android applications. It is dangerous in this context because installing one grants an app the permissions it requests, and these fake documents request access to SMS and notifications so that one-time passcodes can be intercepted.

Turn awareness into measured behaviour

Reading about scams does not change what people click. Claro runs bilingual simulations across email, WhatsApp, SMS and voice, then measures who is actually resilient.

See how Claro measures it