Operation RTO Heist: Anatomy of a Long-Running RTO Phishing Campaign Targeting Indian Users
Android’s dominance in India, combined with the rapid adoption of mobile banking and government-backed digital services, has significantly expanded the mobile threat landscape. Since 2021, we have been tracking a persistent, large-scale malware campaign leveraging Regional Transport Office (RTO)-themed phishing lures, impersonating trusted applications such as mParivahan. What initially appeared to be opportunistic phishing activity has evolved into a highly coordinated, long-running malware ecosystem targeting Indian users at scale.
This research presents a comprehensive analysis of over 1000 Android malware samples associated with this campaign, revealing that these are not isolated threats but components of a structured, multi-stage delivery framework. More than 60% of the analyzed samples rely on a modular dropper architecture, referred to as MiningDropper, which incorporates native code, layered obfuscation, and staged payload execution to evade both static and dynamic detection mechanisms.
A defining characteristic of this campaign is its evolution from broad phishing-based distribution to a more targeted, intelligence-driven victim acquisition model. The threat actors exhibit behaviors similar to Initial Access Brokers (IABs), actively identifying potential victims by monitoring public social media platforms. Specifically, they track complaints, queries, and feedback directed at legitimate services such as mParivahan, IRCTC, and Indian banking institutions. These posts often contain user contact details,
including phone numbers, which are then used by the actors to initiate direct engagement through SMS, messaging applications, and voice calls. By impersonating official support channels, the attackers significantly increase the success rate of their social engineering operations, marking a shift from mass phishing to targeted pretexting and victim profiling.
The technical backbone of this campaign lies in its sophisticated multi-stage dropper architecture. The infection chain begins with user installation of a malicious application delivered via phishing websites or direct communication. Upon execution, the application loads a native library (.so), where critical logic is concealed through XOR- based obfuscation and runtime string decryption. Early-stage execution includes environment validation checks, such as emulator detection based on device properties (e.g., manufacturer, architecture), ensuring that analysis environments are identified and avoided.
The payload delivery process is structured into multiple stages, each employing distinct decryption and execution mechanisms:
- Stage 1: Native code extracts encrypted assets from the application package and decrypts them using XOR-based routines.
- Stage 2: The decrypted output is further processed using AES encryption, where keys are dynamically derived (e.g., using the first 16 bytes of a SHA-1 hash of the filename), introducing variability and complicating static analysis.
- Stage 3 and beyond: Additional payloads are decrypted and prepared, often packaged as compressed archives containing DEX files and native components.
- Final Stage: The dropper installs the final payload using Android’s PackageInstaller APIs, completing the infection chain.
A critical insight uncovered during this research is the presence of state-driven payload execution logic. Rather than a single deterministic path, the dropper dynamically transitions between multiple operational modes, typically labeled internally as “miner” and “user payload.” The execution flow initially favors the mining path, enabling the threat actor to generate immediate revenue through cryptocurrency mining. However, based on runtime conditions and installation callbacks, the dropper can pivot to deploying a secondary payload focused on financial fraud. This design demonstrates a strategic separation between monetization and exploitation, where mining serves as a fallback or camouflage mechanism rather than the primary objective.
The final payload frequently observed in this campaign is Ghostbat RAT, a lightweight yet effective Android remote access trojan specifically tailored for financial fraud.
Ghostbat RAT operates with minimal permissions, relying heavily on SMS access and broadcast receivers to intercept One-Time Passwords (OTPs). It employs UI impersonation techniques, including overlay attacks, to harvest sensitive banking credentials, and communicates with command-and-control (C2) infrastructure using resilient and low-overhead channels.
One notable aspect of Ghostbat RAT’s operation is its use of Telegram Bot APIs for C2 communication. By embedding bot configurations within the malware, the attackers leverage Telegram’s infrastructure to issue commands, receive stolen data, and maintain operational flexibility. Analysis of these bot interactions provided key insights into attacker workflows and infrastructure, enabling partial attribution and tracking of campaign activity.
Beyond Telegram, the campaign extensively abuses legitimate services to enhance reliability, scalability, and evasion. These include:
- GitHub for hosting and distributing malicious APKs
- Firebase for configuration management and backend communication
- Telegram for command-and-control operations
This reliance on trusted platforms complicates detection efforts, as network traffic often appears legitimate and blends with normal user activity.
The campaign also demonstrates continuous evolution over time. Through year-over- year comparative analysis, we observe changes in code structure, encryption routines, payload delivery mechanisms, and infrastructure usage. This iterative development highlights an adaptive threat actor capable of responding to detection measures and refining their techniques to maintain persistence.
From a defensive perspective, this research provides actionable insights into detection and prevention strategies. Key indicators include:
- Suspicious permission combinations (e.g., SMS access combined with package installation capabilities)
- Behavioral anomalies such as dynamic payload loading and staged decryption
- Delivery patterns involving phishing websites and direct social engineering
We also highlight practical approaches to bypass common evasion techniques, including handling ZIP header manipulation, decoding obfuscated strings, and analyzing native-layer decryption routines.
Finally, the session addresses the importance of coordinated response efforts. Given the campaign’s reliance on legitimate services, effective disruption requires collaboration between security researchers, platform providers, and government entities. We discuss real-world takedown strategies, including infrastructure identification, abuse reporting, and coordinated remediation actions that can significantly reduce the campaign’s impact.
This talk provides a complete, end-to-end view of a long-running Android malware operation targeting India’s digital ecosystem. By combining large-scale sample analysis, technical deep dives, and campaign-level intelligence, we aim to equip security practitioners with the knowledge required to detect, analyze, and mitigate similar multi-stage threats in the future.

Rupali Parate – Cyble
Rupali Parate is a cybersecurity researcher specializing in malware analysis, reverse engineering, and cyber threat intelligence, with a focus on uncovering and tracking advanced threats across the mobile ecosystem. Her work involves dissecting complex malware, analyzing adversary behavior, and transforming deep technical findings into actionable intelligence for security teams.
She has led large-scale investigations into sophisticated malware campaigns, exposing attacker infrastructure and operational techniques. Her research has been widely cited and featured in leading cybersecurity and mainstream media, reflecting the real-world impact and relevance of her findings.
Rupali’s work also extends to scalable threat intelligence, automated detection engineering, and adversary attribution, enabling organizations to identify, track, and respond to emerging campaigns with greater speed and precision.