Sunday, July 19, 2026

Warning: Cybercriminals Distributing Malicious Apps Disguised as Wedding Invitations

May 12, 2026
Warning: Cybercriminals Distributing Malicious Apps Disguised as Wedding Invitations
Warning: Cybercriminals Distributing Malicious Apps Disguised as Wedding Invitations

Hyderabad residents and mobile users across India are being targeted by a growing scam involving deceptive wedding invitation files that install harmful software on smartphones.

Cybercriminals have been circulating malware-laden applications under names such as "Marriage Invitation.apk" and "Wedding Card.apk" through WhatsApp, SMS, and other digital messaging channels. Once installed, these trojanized applications pose significant security risks to users' personal and financial data.

Authorities have flagged that the embedded malware possesses the capability to harvest contact lists, photograph galleries, text message archives, and sensitive personal details stored on compromised devices. The threat extends further, as the malicious code can penetrate banking software, intercept one-time passwords used for authentication, and gain remote command over infected phones.

A particularly concerning aspect of this scam is its self-propagating nature. Compromised devices may automatically disseminate the same fraudulent invitation files to the victim's contacts, amplifying the reach of the attack.

Security officials have issued clear guidance for protection: avoid downloading APK files from messaging applications, SMS links, or unverified sources. Instead, users should obtain applications exclusively through legitimate platforms like Google Play Store or Apple App Store. Before opening any file, especially from unfamiliar senders, verification is essential.

Maintaining current mobile security patches and deploying reputable antivirus software are additional protective measures recommended by cybersecurity professionals.

For those who have already installed such applications, immediate action is necessary. Users should cut off internet connectivity, remove the suspicious application from their device, and reset all passwords. Subsequently, they should review recent banking transactions for unauthorized activity. Those affected can lodge complaints via helpline 1930 or file reports through the National Cyber Crime Portal.

Compare options