Top News

UPI is vulnerable to 'Luthor' malware; keep your account safe; any error could lead to losses.
KalamTimes | March 12, 2026 9:41 PM CST

UPI Safety Tips: UPI users are currently facing the threat of a new malware. This malware is installed on phones via APK files and operates in the background.

 

A new malware threat is looming over UPI payments.

UPI Safety Tips: If you use UPI payments or net banking, you need to be wary of banking-related scams. Recently, a new malware called "Digital Lutera" was discovered, which can steal money from your UPI account. This malware doesn't rely on calling or messaging to carry out its scams; it directly gains access to your Android phone. Let's explore what this malware is and how to protect yourself from it.

What is 'Digital Looter'?

Gadgets360 first reported on this malware. It doesn't operate like traditional scams, where scammers hack into a user's account by sending a link via a call or message. This is a different type of fraud toolkit that can bypass UPI bank account and SMS-based OTP verification. This malware enters a user's device through APK files and then performs its work once permission is granted.

How does this malware work?

This malware is being distributed through APK files. As soon as a user downloads the infected APK file, it will be installed on their device. During installation, the APK file will ask for permission to write and read SMS. Once permission is granted, the malware begins its work. Operating in the background, it silently monitors bank verification messages, allowing the hackers controlling the malware to breach users' accounts.

NPCI has clarified

NPCI (National Payments Corporation of India), which operates the UPI platform, has issued a clarification on this matter. NPCI stated that it has analyzed reports of this malware and has implemented adequate measures within UPI to protect users from such risks.

How to avoid such scams?

  • If you use an Android phone, download apps only from trusted sources like Google Play Store.
  • If someone sends you a link via message asking you to download an APK file, refuse. Never download apps from such links.
  • Keep Google Play Protect turned on on your phone and keep your phone's software updated.


READ NEXT
Cancel OK