📷 Image: Wikimedia Commons / torbakhopper
Technology
Malicious Apps Exploit UPI Permissions to Steal OTPs, Warn Experts
✍️ NDTV Top
🗓 07 Sep 2026, 08:41 AM
👁 3
Security analysts say rogue applications can misuse accessibility and notification permissions to read OTPs and drain UPI accounts, highlighting a growing mobile fraud threat.
Security researchers have identified a new vector for financial fraud that leverages seemingly harmless Android applications. Once a user installs such an app, it can request accessibility, notification and other high‑risk permissions. These privileges enable the software to monitor screen activity, capture incoming one‑time passwords (OTPs) and even trigger unauthorized UPI transactions.
The technique, often described as a "frozen‑screen" glitch, tricks users into believing the app is idle while it silently records OTPs sent by banks. With the OTP in hand, the malicious code can complete a payment without the victim’s knowledge, effectively draining the account.
Experts advise users to install apps only from trusted sources, scrutinize permission requests, and disable accessibility services for apps that do not require them. Banks are also urged to strengthen OTP delivery mechanisms and educate customers about the risks of granting excessive permissions.
The UPI ecosystem, which processes billions of transactions daily, remains a prime target for cyber‑criminals. Continuous vigilance from both users and financial institutions is essential to curb this emerging threat.
The technique, often described as a "frozen‑screen" glitch, tricks users into believing the app is idle while it silently records OTPs sent by banks. With the OTP in hand, the malicious code can complete a payment without the victim’s knowledge, effectively draining the account.
Experts advise users to install apps only from trusted sources, scrutinize permission requests, and disable accessibility services for apps that do not require them. Banks are also urged to strengthen OTP delivery mechanisms and educate customers about the risks of granting excessive permissions.
The UPI ecosystem, which processes billions of transactions daily, remains a prime target for cyber‑criminals. Continuous vigilance from both users and financial institutions is essential to curb this emerging threat.