{"id":85326,"date":"2017-12-14T19:51:32","date_gmt":"2017-12-14T14:21:32","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=85326"},"modified":"2017-12-15T17:53:49","modified_gmt":"2017-12-15T12:23:49","slug":"beware-fake-apps-claim-link-mobile-number-aadhaar","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/beware-fake-apps-claim-link-mobile-number-aadhaar\/","title":{"rendered":"Beware of fake apps that claim to link your mobile number to Aadhaar"},"content":{"rendered":"<p>Are you looking for ways to avoid visiting your cellular network provider\u2019s care center\/store to get your Aadhaar linked to your mobile number? Have you recently searched for apps that can help you do this? Well, here is some important and useful information for you.<\/p>\n<p>It is now mandatory for all mobile users to link their Aadhaar to their mobile number. According to an advisory issued by the Unique Identification Authority of India (UIDAI), mobile users do not have to visit any store to get the Aadhaar-phone linking done. This can be done with a voice-guided system through a one-time password (OTP) from 1<sup>st<\/sup>\u00a0January 2018, as reported by <a href=\"https:\/\/timesofindia.indiatimes.com\/india\/from-jan-1-link-your-mobile-to-aadhaar-via-otp\/articleshow\/61991997.cms\"><u>Times of India<\/u><\/a>.<\/p>\n<p>Quick Heal Security Labs came across an app on the Google Play Store that claimed to help users link their mobile number to Aadhaar. For obvious reasons, we found the occurrence of this app suspicious because <strong><b>the UIDAI has not spoken about any mobile app which can be used for Aadhaar-phone linking.<\/b><\/strong><\/p>\n<p>As expected, we found the app to be fake and not related to UIDAI. This is what it looks like.<\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_85327\" aria-describedby=\"caption-attachment-85327\" style=\"width: 815px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-85327\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/12\/Image1.png\" alt=\"Fig 1. The fake app\u2019s interface displaying a fake biometric authentication mechanism.\" width=\"815\" height=\"430\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/Image1.png 815w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/Image1-300x158.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/Image1-768x405.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/Image1-650x343.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/Image1-789x416.png 789w\" sizes=\"(max-width: 815px) 100vw, 815px\" \/><figcaption id=\"caption-attachment-85327\" class=\"wp-caption-text\">Fig 1. The fake app\u2019s interface displaying a fake biometric authentication mechanism.<\/figcaption><\/figure>\n<p><strong>This app was downloaded over 1,00,000 times and was removed from Google Play after Quick Heal Security Labs reported it to Google.<\/strong><\/p>\n<p><strong><b>\u00a0<\/b><\/strong><strong><b>An interesting observation<\/b><\/strong><\/p>\n<p>One interesting thing which we observed during our analysis is this app can send you an OTP even if you don\u2019t have a SIM card in your phone. Wonder how this works? A simple trick used by the app developer answers this question. The OTP sent for the verification is just a pop-up notification generated by the app to fool the user. This notification looks similar to the ones which are displayed at the top part of your mobile screen whenever you receive a new SMS. Fig 2 below shows how the fake OTP notification appears. Extremely tricky, isn\u2019t it?<\/p>\n<p><strong><b>Our verdict<\/b><\/strong><\/p>\n<p>This fake app is nothing but a source of income for the app developer which they generate by serving unwanted ads to the user. This app does not benefit the user in any way and even worse, it can also be used to steal their Aadhaar information. Such stolen information can be used for identify theft and other such crimes.<\/p>\n<figure id=\"attachment_85328\" aria-describedby=\"caption-attachment-85328\" style=\"width: 231px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-85328 size-full\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/12\/image2.png\" alt=\"Fig 2. OTP generated by the app.\" width=\"231\" height=\"419\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image2.png 231w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image2-165x300.png 165w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image2-215x390.png 215w\" sizes=\"(max-width: 231px) 100vw, 231px\" \/><figcaption id=\"caption-attachment-85328\" class=\"wp-caption-text\">Fig 2: OTP generated by the app.<\/figcaption><\/figure>\n<p>Quick Heal Security Labs analyzed similar apps on the Play Store and found many with names related to Aadhaar and mobile phone linking. Most of these apps name themselves as \u2018prank\u2019, \u2018guide to linking Aadhaar to mobile\u2019, and \u2018just for entertainment\u2019 in their descriptions which are usually not noticed by most users (fig 3).<\/p>\n<p>We strongly recommend you to always read the description of an app you want to install on your device. Just because an app describes itself as a prank app, it does not mean it is safe to use.<\/p>\n<figure id=\"attachment_85329\" aria-describedby=\"caption-attachment-85329\" style=\"width: 853px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-85329\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/12\/image3.png\" alt=\"Fig 3. One of the app\u2019s description.\" width=\"853\" height=\"145\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image3.png 853w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image3-300x51.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image3-768x131.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image3-650x110.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/image3-789x134.png 789w\" sizes=\"(max-width: 853px) 100vw, 853px\" \/><figcaption id=\"caption-attachment-85329\" class=\"wp-caption-text\">Fig 3: One of the app\u2019s description.<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p><strong><b>Further observations<\/b><\/strong><\/p>\n<p>There was a sudden rise in the number of people searching the Internet for the term \u201clink Aadhaar number to mobile number\u201d on Dec 1, according to the Google Trends survey for India. Noticeably, on this very day, UIDAI had given its approval to telecom community\u2019s request to make the Aadhaar-mobile linking facility available online. Fig 4 shows the trends.<\/p>\n<figure id=\"attachment_85330\" aria-describedby=\"caption-attachment-85330\" style=\"width: 1152px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-85330\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/12\/trend.png\" alt=\"Fig 4: Sudden increase on Dec 1 for the search query \u201clink Aadhaar number to mobile number\u201d in India.\" width=\"1152\" height=\"395\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/trend.png 1152w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/trend-300x103.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/trend-768x263.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/trend-650x223.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/12\/trend-789x271.png 789w\" sizes=\"(max-width: 1152px) 100vw, 1152px\" \/><figcaption id=\"caption-attachment-85330\" class=\"wp-caption-text\">Fig 4: Sudden increase on Dec 1 for the search query \u201clink Aadhaar number to mobile number\u201d in India.<\/figcaption><\/figure>\n<p><strong><b>To reiterate, currently there is no app which will provide you with in-app biometric Aadhaar to mobile linking facility.<\/b><\/strong><\/p>\n<p><strong><b>How to stay safe from fake mobile apps<\/b><\/strong><\/p>\n<ol>\n<li>Check an app\u2019s description before you download it.<\/li>\n<li>Check the app developer\u2019s name and their website. If the name sounds strange or odd, you have reasons to suspect it.<\/li>\n<li>Go through the reviews and ratings of the app. But, note that, these can be faked too.<\/li>\n<li>Avoid downloading apps from third-party app stores.<\/li>\n<li>Use a reliable <a href=\"https:\/\/bit.ly\/2isL3JA\"><u>mobile antivirus<\/u><\/a> that can prevent fake and malicious apps from getting installed on your phone.<\/li>\n<\/ol>\n<p>Note: We searched the Play Store and found apps with the following package names. These apps claim to link phone number to Aadhaar but they are mostly prank apps or guides and do not provide the actual facility.<\/p>\n<table style=\"height: 1000px;\" width=\"916\">\n<tbody>\n<tr>\n<td width=\"356\"><strong><b>Package<\/b><\/strong><\/td>\n<td width=\"340\"><strong><b>App Name<\/b><\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.linkAadhaar.Aadhaarcardlinktomobile<\/td>\n<td width=\"340\">Aadhaar Card Link to Mobile Number \/ SIM Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.linkAadhaar.Aadhaarcardlinktomobilenumber<\/td>\n<td width=\"340\">Link Aadhaar Card to Mobile Number \/SIM Card Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">phototool.app.Aadhaarcardlinktomobile<\/td>\n<td width=\"340\">Link Aadhaar Card with Mobile Number &amp; SIM Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">smartappcorner.Aadhaarcardlinkwithmobile<\/td>\n<td width=\"340\">Link Aadhaar Card to Mobile Number &amp; SIM Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.IndianServices.LinkAadhaarCardwithMobileNumber<\/td>\n<td width=\"340\">Link Aadhaar With Mobile<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">fabia.dev.linkAadhaarwithsim<\/td>\n<td width=\"340\">Aadhaar Card Linkk To Mobile Number<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.stoff.linkAadhaartomobile<\/td>\n<td width=\"340\">Free Link Aadhaar Card to Mobile Number \/SIM Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">smartappcorner.onlineAadhaarlinksim<\/td>\n<td width=\"340\">Free Aadhaar Card Link to SIM Card<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">world.studio.classes.mobileno.toadhar.lab<\/td>\n<td width=\"340\">Link Aadhaar Card to Mobile Number &amp; SIM Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.link.Aadhaar.card.with.mobile.number<\/td>\n<td width=\"340\">Link Aadhaar Card with Mobile Number Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.tomobilenumber.linkAadhaarcard<\/td>\n<td width=\"340\">Link Aadhaar to Mobile Sim Number<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.crazy.linkAadhaarwithsimcard<\/td>\n<td width=\"340\">Link Aadhaar To Mobile No<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.link.adhartomob<\/td>\n<td width=\"340\">Link Aadhaar Card with Mobile Number<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.photovideovalley.linkAadhaarwithmobile<\/td>\n<td width=\"340\">Link Aadhaar Card with Mobile Number &amp; SIM Online<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">daily.apps.linkAadhaarwithmobilenumber<\/td>\n<td width=\"340\">Link Aadhaar to Mobile Number<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">com.smartdev.linkAadhaar<\/td>\n<td width=\"340\">Link Aadhaar Card with Mobile Number free<\/td>\n<\/tr>\n<tr>\n<td width=\"356\">adhar.tool.Aadhaarcardlinktomobile<\/td>\n<td width=\"340\">Aadhaar Card Link to Mobile Number<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Subject Matter Expert<\/p>\n<p>Omkar Gurav | Quick Heal Security Labs<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Are you looking for ways to avoid visiting your cellular network provider\u2019s care center\/store to get your Aadhaar linked to your mobile number? Have you recently searched for apps that can help you do this? Well, here is some important and useful information for you. It is now mandatory for all mobile users to link [&hellip;]<\/p>\n","protected":false},"author":37,"featured_media":85332,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55],"tags":[431,1524],"class_list":["post-85326","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","tag-android","tag-fake-app"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/85326"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=85326"}],"version-history":[{"count":11,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/85326\/revisions"}],"predecessor-version":[{"id":85345,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/85326\/revisions\/85345"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/85332"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=85326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=85326"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=85326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}