Government / Malware

The Fake ETLE Traffic Ticket with a Malicious App

This lure combines authority and fear: a fake electronic traffic ticket that tricks victims into installing an Android app which quietly drains their mobile banking. This walkthrough is a fictional, illustrative example built for training.

The scenario

A WhatsApp message arrives claiming to be an official electronic traffic law enforcement (ETLE) notice, stating that the recipient's vehicle was recorded committing a violation. The sender's profile may use a police logo to look official.

Rather than a link, the message includes a file that looks like a document, for example 'Surat.Tilang.Elektronik.apk'. The recipient is told to open the attachment to see the photo evidence and pay the fine before a deadline.

The file is not a document but an Android application (APK). Installing it prompts the victim to grant broad permissions, such as reading SMS and acting as the default messaging app. This lets the malware intercept the one-time passwords banks send by SMS.

With SMS interception and other permissions in place, the attacker can log into the victim's mobile banking and authorize transfers using the stolen OTPs, often at night, while the malware hides the confirmation messages from the victim.

Red flags to spot

An .apk file attached to a message

Official notices are never delivered as an app you must install. An APK from a chat is almost always malware, especially when it is disguised as a 'document'.

The 'ticket' arrives via WhatsApp instead of an official channel

Real ETLE enforcement sends a physical confirmation letter to the address registered to the vehicle, not an unsolicited WhatsApp attachment.

The app requests permission to read SMS or become the default SMS app

Legitimate document viewers do not need SMS access. This permission exists so the malware can steal the OTP codes that protect your bank account.

Pressure to pay a fine quickly to avoid escalation

Fear of legal consequences is used to rush you into installing the file before you stop to verify through the official ETLE website.

The file name ends in .apk even though it claims to be a letter or photo

A genuine letter or image would be a PDF or image file. An .apk extension always means an installable program, never a document.

The lesson

Never install an application sent to you through WhatsApp or any chat, no matter how official the message looks; a file ending in .apk is a program, not a document. Real ETLE violations are confirmed through the official ETLE website and a physical letter sent to the vehicle's registered address, and fines are paid through official banking channels with a proper billing code, never by opening an attachment. If you receive such a message, do not tap the file, delete it, and verify any genuine concern on the official ETLE portal. If you already installed the app, disconnect from the internet, contact your bank immediately, and have the device checked by IT.

These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.

Frequently asked questions

  • Through the official ETLE process: a confirmation letter is sent to the address registered to the vehicle, and details can be checked on the official ETLE website. It is never sent as a WhatsApp attachment you must install.

Run these patterns as real simulations

Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.

Request a demo