Mobile malware / social

The Wedding Invitation That Is Not An Invitation

This variant deserves its own entry because it defeats the usual advice. People are trained to distrust messages about money, but an invitation triggers curiosity and social obligation instead of suspicion.

How the scam runs

A message arrives with a warm, personal tone and a file named like a wedding invitation. The sender is often a number the recipient does not recognise, which in most contexts would be a warning, but for an invitation it reads as ordinary: guests routinely receive invitations from numbers they have not saved.

Curiosity does the work that urgency does in other scams. The recipient wants to know whose wedding it is, and whether they have overlooked someone they know. Opening the file offers to install an application, which many people accept because they assume a digital invitation needs a viewer.

From there it behaves identically to any malicious APK: SMS and notification permissions, interception of one-time passcodes, and access to financial accounts. The same pattern circulates as delivery receipts, tax notices and traffic fines, but the invitation version consistently performs best.

Signals that give it away

A digital invitation should be a link or an image, never an app

Real digital invitations are web pages, PDFs or images. No invitation requires you to install software. If viewing it needs an installation, it is not an invitation.

The file name looks like a document but ends in .apk

Attackers name files to read as documents, sometimes with a fake extension earlier in the name. Check what the name actually ends with, because that is what determines how the phone treats it.

You cannot identify the couple, and the message avoids specifics

A genuine invitation names people, a date and a venue in the message itself. Vagueness paired with an attachment means the attachment is the point, not the event.

The one rule that stops it

Curiosity is the payload here, not urgency. If you cannot identify who is getting married from the message text alone, there is nothing to open. Ask the sender directly through a channel you trust.

These pages describe fraud tactics for defensive awareness and staff briefing purposes. They are general information, not legal or financial advice. If you have lost money, report it through official channels: the police cyber crime unit, your bank, and for investment or lending matters, OJK.

Frequently asked questions

  • The .apk cannot install on iOS, so that specific file will not run. Do not treat the message as harmless though, since the same campaigns send phishing links to iPhone users. Delete it either way.

Turn awareness into measured behaviour

Reading about scams does not change what people click. Claro runs bilingual simulations across email, WhatsApp, SMS and voice, then measures who is actually resilient.

See how Claro measures it