The Indian government has ordered Google to remove dozens of websites and databases hosted on its Firebase platform after finding that cybercriminals were allegedly using the service to impersonate banks, distribute malware and steal sensitive financial information. Notices from the Indian Cyber Crime Coordination Centre (I4C) show that at least 57 Firebase-hosted websites and databases were targeted for removal in August.
As per govt notices, several websites were created to resemble the online services of major Indian banks, including SBI, ICICI Bank and Axis Bank. Seven of the 57 websites were reportedly phishing pages impersonating banks, while others were allegedly used to collect information stolen from victims’ smartphones.
The I4C said some campaigns involved Android malware disguised as legitimate banking apps. The victims were reportedly targeted with offers for new credit cards, reward redemptions and higher credit limits before being asked to install an application. The malware can then steal sensitive information, including credit card details and one-time passwords and send the data to infrastructure controlled by attackers.
Another campaign allegedly exploited the PM-KISAN government scheme. The scammers reportedly promised victims help in claiming their payments and directed them to download a malicious app. Once installed, the application can transmit data from the victim’s smartphone to the Firebase database controlled by the attackers.
Also read: Redmi Note 17 Pro India launch timeline, specifications, price and all other latest leaks
Many malware campaigns have been described by cybersecurity researchers as Android God Mode, referring to malicious applications that can potentially gain extensive access to an infected Android device and data stored across other apps.
Firebase, which is utilized by millions of developers worldwide, is Google’s platform for the development and hosting of websites and applications. Indian authorities are of the opinion that scammers have been increasingly attracted to legitimate cloud services due to their database capabilities and free offerings.
The I4C notices allegedly gave Google three hours to remove the links that had been flagged, threatening legal action against the firm if the links were left visible. However, Google has stated that it has stringent regulations in place to combat phishing, malware, and financial fraud, and that it collaborates with law enforcement organizations, such as the I4C, to examine and address allegations of abuse.