Skip to main content

Command Palette

Search for a command to run...

Series

Not (a) Fine

A ground up investigation into a real smishing campaign targeting users through a fake MoRTH eChallan notification.

What starts as a suspicious SMS turns into a four-stage dropper framework: custom encryption, bulletproof C2 infrastructure, VPN traffic interception and a final banking trojan payload.

Every layer, reverse engineered.