Fraudsters are reportedly using messaging apps like WhatsApp and Telegram to distribute a malicious Android application file disguised as an official airline tool.
According to the police, the scam involves sending users a file named "SriLankan.apk" alongside convincing messages about flight offers or promotions. When a user clicks the link to download the file, it silently installs a banking trojan on their Android device. This malware is designed to steal sensitive data, including One-Time Passwords (OTPs), bank account credentials, and even biometric information such as fingerprints and facial recognition data used for banking apps.
The police have identified several phone numbers currently being used to facilitate this fraud, including 077-4558361, 074-1142208, 077-5791209, and 074-3268200. Authorities warn that once the malicious app is installed, hackers gain remote access to the victim's phone, allowing them to monitor SMS messages and intercept the authentication codes required to transfer funds out of bank accounts.
SriLankan Airlines has officially distanced itself from these communications, clarifying that the airline never contacts customers via WhatsApp to share files or request sensitive financial details. The national carrier emphasized that they will never ask for OTPs, PINs, or for customers to install third-party applications via links sent through messaging services.
The public is strongly advised to refrain from downloading any files with the .apk extension received from unknown sources.