TL;DR: India's Indian Cyber Crime Coordination Centre (I4C) has warned government employees about a WhatsApp scam offering an '8th Pay Commission salary calculator' — the file is actually a malicious APK designed to gain full access to the victim's phone and drain their bank account. It works because the 8th Pay Commission is a real, widely-anticipated topic — the scam simply rides that genuine interest.

👉 Check what's already exposed about your own accounts — free scan →

The 8th Pay Commission genuinely matters to millions of Indian government employees waiting on updated salary structures — which is exactly the real anticipation this scam exploits. Messages circulate on WhatsApp offering a "salary calculator" app that promises to show exactly what an employee's new pay will look like under the revised commission. Instead of a calculator, the download is a malicious Android APK file.

How the malware actually works

Once installed, the fake calculator app requests broad device permissions — often including SMS access, accessibility services, and overlay permissions — under the guise of "verifying" employee details. In practice, these permissions let the malware intercept OTP messages, log keystrokes on banking apps, and in some cases display fake overlay screens on top of real banking apps to capture login credentials directly. This combination gives attackers everything needed to drain a linked bank account without the victim noticing until money is already gone.

Why this specific scam is dangerous

How to protect yourself

If you've already installed it

Disconnect from the internet immediately (turn on airplane mode), then use another device to change your banking passwords and contact your bank to flag the account. Uninstall the malicious app, or if that's not possible, consider a full factory reset after backing up essential (non-banking-app-linked) data. Report the incident at cybercrime.gov.in or call 1930.

FAQs

What permissions does this malicious app typically request?

Commonly SMS access, accessibility services, and overlay permissions — together, these let attackers intercept OTPs, log activity in banking apps, and in some cases display fake screens over real apps to capture login details.

Why doesn't this app get caught by my phone's normal security?

APK files installed outside the Play Store bypass Google's automatic malware scanning, which is why sideloading an APK from an unofficial source removes a major layer of built-in protection.

What should I do if I already installed the fake salary calculator?

Put the phone in airplane mode immediately, use a different device to change your banking passwords and alert your bank, uninstall the app or factory reset if needed, and report the incident at cybercrime.gov.in or call 1930.

Curious what's already out there? Scan My Shadow checks a phone number and email across 1,500+ sources and sends a clear report — no guesswork, just facts. Start your scan.

Related Reading