thread.news
← Back
BGenerally CredibleFinance🌐Global⚠ Coverage gap9/7/2026, 4:00:35 AM
Understanding the 'Frozen Screen' UPI Scam and How Malicious Apps Operate

Understanding the 'Frozen Screen' UPI Scam and How Malicious Apps Operate

A new form of digital fraud involves malicious applications that exploit mobile permissions to intercept sensitive banking information. These apps can monitor user activity and read one-time passwords (OTPs) to facilitate unauthorized transactions.

Share
📈

Market Narrative Detected

The narrative focuses on the vulnerability of digital payment systems to user-side errors, benefiting cybersecurity firms and banks by shifting the burden of security onto the individual consumer.

Coverage
leftcenterrightinternationalinvestigative

A growing security threat known as the 'frozen screen' scam is targeting users of Unified Payments Interface (UPI) and mobile banking services. According to security reports, the process begins when a victim is tricked into installing a malicious application on their smartphone. Once granted specific permissions—such as accessibility services and notification access—the app gains the ability to monitor the user's screen activity in real-time.

In many instances, the malware is designed to trigger a 'frozen' or unresponsive screen, which serves as a distraction while the application operates in the background. During this period, the software can intercept incoming SMS messages, including critical one-time passwords (OTPs) required to authorize financial transactions. By capturing these codes, attackers can bypass security protocols and drain funds from the victim's linked bank accounts without the user's immediate knowledge.

Security experts emphasize that these scams rely heavily on social engineering, where users are manipulated into granting high-level permissions to apps that appear legitimate or are presented as necessary for 'technical support' or 'glitch resolution.' Once the permissions are active, the malware effectively takes control of the device's communication channels. To mitigate these risks, cybersecurity professionals advise users to avoid downloading applications from unofficial sources, to carefully review permission requests before installation, and to remain vigilant against unsolicited requests for remote access or app downloads.

📡 Media Analysis

How each outlet framed the story — angles, word choices, and what they chose to push or ignore.

NDTVCenterA+

Focused on the technical mechanics of the scam to educate the reader on security risks.

"malicious applications can abuse accessibility"

"malicious applications""technical 'glitch'"

🔍 What Nobody's Reporting

  • ·Lack of specific data on the prevalence or geographic distribution of these attacks.
  • ·No information provided on how victims can recover funds once the theft has occurred.
  • ·Absence of advice on how to identify and remove these specific malicious apps once installed.

📰 Sources

0 A-rated source(s) among 1 total. Lowest trust: NDTV (B)