How to identify illegal/Chinese loan Apps?

Rushi Mehta
2 min readAug 6, 2022

--

Mobile Apps could cause a massive trouble if not used safely. Recently there has been a huge surge in illegal lending apps getting uploaded on Google Playstore. How to identify if Ads are genuine? Following are some ways…

How to reach 50 Crore Indians?

Massive Digital Advertisement + Fake International Reviews + Bulk SMS

1. App Reviews : Check for 5 Star Reviews and Content

To boost the Mobile Application, fake reviews are posted with unrelated content. Presently it is seen all reviews are from international accounts. Now some app have fake Indian Reviews.

Fake International Reviews

2. App Advertisements : Verify.

Instant Loan apps reach to crores of Indians using Advertisement on Google as well as Facebook. To check the details of uploader, click on “Three dots” button present besides Ads. If it is an advertisement, install after caution.

Most of apps use Google/Facebook Advertisement

3. App Developer Details : Gmail

Majority of fraudulunt loan apps are registered by gmail developer details.

Corporate Apps generally have their own domains rather than using gmail

4. App Message/OTP

All Instant Loan app use OTP based login. OTP will be received from unrelated SMS Header and content.

For Large_Taka App, OTP came from Indus Portfolio.

5. App Permissions

Go to Data Safety → About this app in Playstore. These suspected loan app use all permissions from your phone including contacts, location, storage etc.

For mobile security researchers:

AWS compute and Alibaba India servers are using for hosting these apps due to which domains many not appear malicious.

“1.1.1.1” WARP app by Cloudflare service is used by criminals which will hide their login-log off logs.

Focus on embedded links of Payment Aggregators and Fintech companies in code. Ex. Advanced AI, CashFree, RazorPay, PayU, Paytm etc.

Hunt for SMS header information from DLT platform via TRAI’s website..

Closing Thoughts

. Even the safest of mediums can be a house of scary apps. Do not download any app that you don’t need or have a separate phone only for ‘entertainment’.

--

--

Rushi Mehta
Rushi Mehta

Written by Rushi Mehta

Cyber Security & Fintech Risk Enthusiast, Trekker, Meditator and Contributor!

No responses yet