The Fake ETLE Traffic Ticket with a Malicious App
This lure combines authority and fear: a fake electronic traffic ticket that tricks victims into installing an Android app which quietly drains their mobile banking. This walkthrough is a fictional, illustrative example built for training.
The scenario
A WhatsApp message arrives claiming to be an official electronic traffic law enforcement (ETLE) notice, stating that the recipient's vehicle was recorded committing a violation. The sender's profile may use a police logo to look official.
Rather than a link, the message includes a file that looks like a document, for example 'Surat.Tilang.Elektronik.apk'. The recipient is told to open the attachment to see the photo evidence and pay the fine before a deadline.
The file is not a document but an Android application (APK). Installing it prompts the victim to grant broad permissions, such as reading SMS and acting as the default messaging app. This lets the malware intercept the one-time passwords banks send by SMS.
With SMS interception and other permissions in place, the attacker can log into the victim's mobile banking and authorize transfers using the stolen OTPs, often at night, while the malware hides the confirmation messages from the victim.
Red flags to spot
An .apk file attached to a message
Official notices are never delivered as an app you must install. An APK from a chat is almost always malware, especially when it is disguised as a 'document'.
The 'ticket' arrives via WhatsApp instead of an official channel
Real ETLE enforcement sends a physical confirmation letter to the address registered to the vehicle, not an unsolicited WhatsApp attachment.
The app requests permission to read SMS or become the default SMS app
Legitimate document viewers do not need SMS access. This permission exists so the malware can steal the OTP codes that protect your bank account.
Pressure to pay a fine quickly to avoid escalation
Fear of legal consequences is used to rush you into installing the file before you stop to verify through the official ETLE website.
The file name ends in .apk even though it claims to be a letter or photo
A genuine letter or image would be a PDF or image file. An .apk extension always means an installable program, never a document.
The lesson
Never install an application sent to you through WhatsApp or any chat, no matter how official the message looks; a file ending in .apk is a program, not a document. Real ETLE violations are confirmed through the official ETLE website and a physical letter sent to the vehicle's registered address, and fines are paid through official banking channels with a proper billing code, never by opening an attachment. If you receive such a message, do not tap the file, delete it, and verify any genuine concern on the official ETLE portal. If you already installed the app, disconnect from the internet, contact your bank immediately, and have the device checked by IT.
These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.
Frequently asked questions
Through the official ETLE process: a confirmation letter is sent to the address registered to the vehicle, and details can be checked on the official ETLE website. It is never sent as a WhatsApp attachment you must install.
Related pages
Fake Prize or Lucky-Draw Winner Notice
A message says you have won a prize in a bank, telco, or brand lucky draw, then asks you to pay a 'tax' or share an OTP to claim it, a prize that never existed.
Learn moreIT Password Reset
A fake IT alert warns that your password or account is about to expire, pushing you to click a login link in a hurry.
Learn moreFake Invoice
An email disguised as an unpaid invoice pressures the recipient to pay quickly to avoid a late fee or service suspension.
Learn moreRun these patterns as real simulations
Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.
Request a demo