Cybersecurity Reach Foundation
← All safety alerts
investigatingBrand: Indian traffic authorities

Fake e-challan texts may use legal threats to install an Android app

A text claims that an e-challan has been issued and threatens legal action unless a penalty is paid immediately. The message uses a shortened link instead of an official traffic or government address. The submitted report says the link downloads an Android APK described as a Trojan; the file was not available for independent analysis. Do not open the link or install the app. Check fines through the official government or traffic service opened independently.

Extracted e-challan app logo from the reported Android APK.
The reported APK uses an e-challan logo, but an app logo does not prove that an official traffic authority created the app.

Observed domain or link

  • tinyurl[.]com/PayChaIIan-qc7t36rg

What to do

  • Do not click the shortened link or install the APK.
  • Check any traffic fine through the official government or traffic-authority website or app that you find yourself.
  • Delete the message and report it through your mobile provider or messaging app.
  • If you installed the APK, disconnect the phone from the internet and ask a qualified technician or trusted adult for help.
  • From a separate clean device, change important passwords and review banking and messaging accounts if you opened or installed the app.
  • Contact your bank immediately if you entered payment information or approved an unexpected transaction.

What this alert does not establish

  • The report says the link downloads an APK described as a Trojan, but the APK itself was not available for independent analysis. The message does not establish who created the link or how many people received it.

Share this warning

This alert is also on WatchOut, our shareable alert feed, with one-tap sharing and free email alerts.

Last updated:

This alert is maintained from the shared Cybersecurity Reach Foundation / ScamArchive alert record.