Back to All Advisories
Published byCyberExpert Threat Research Desk
Malware & APKs
5 min read
2 Mar 2026

Electricity Bill Power-Cut Fraud: Anatomy of the Urgent 7:00 PM Malicious APK Trap

Why thousands of consumers receive SMS warnings about imminent power disconnection at 7:00 PM, and how fake payment APK files gain complete SMS accessibility on Android devices.

Advertisement
Active Scam In Progress? Take Action in 3 Steps:1. Hang up the call or disconnect the WhatsApp/Skype feed immediately.
2. Dial 1930 (National Cyber Emergency Helpline) to freeze recipient bank accounts.
3. File an official complaint on cybercrime.gov.in.

## Anatomy of the Electricity Bill Power-Cut Vector

The **"Electricity Power Cut at 7:00 PM or 9:30 PM"** scam is a precision social engineering attack designed around the fear of darkness and disruption to domestic life.

The Social Engineering Trigger A typical SMS arrives from an unregistered personal mobile number (`+91 98xxx xxxxx`): ``` Dear Consumer, Your electricity connection will be disconnected tonight at 7:30 PM from the electric substation because your previous month's bill was not updated. Please immediately call our electricity officer at 9876543210. ```

Why the 7:00 PM Deadline? The scam intentionally specifies a tight evening deadline (between 6:00 PM and 9:00 PM): - Official electricity board offices are closed, making in-person verification impossible. - Family members are returning home, cooking, or watching TV, amplifying the immediate fear of a blackout. - Victims make hurried, irrational decisions under time stress.

The Malicious APK Delivery Mechanism When the consumer panics and calls the phone number: 1. The scammer answers courteously, pretending to check the consumer database. 2. They state: *"Sir, your ₹10 or ₹12 update fee is pending in the automated gateway. Please install our official Bijli Seva app so we can update your payment status instantly."* 3. The scammer sends an APK file via WhatsApp with names such as `Suvidha.apk`, `Electricity_Update.apk`, or `Mahavitaran_Service.apk`.

Device Takeover & Invisible OTP Interception Once installed: - The app prompts for accessibility services and **READ_SMS** permissions. - It asks the victim to make a nominal ₹10 test payment using net banking or a debit card. - As the user enters card credentials and PIN, the keylogger records every keystroke. - When the bank transmits the critical transaction OTP, the malware intercepts the SMS silently and relays it to an attacker-controlled Telegram Bot before deleting the SMS notification from the victim's notification shade. - Within minutes, recurring transfers drain the victim's primary bank account.


Defensive Action Rules

1. **Verify Sender ID**: Genuine discoms never send disconnection warnings from standard 10-digit personal phone numbers. 2. **Never Side-Load APKs**: Never download files ending in `.apk` shared over WhatsApp, Telegram, or Google Drive links. Official apps exist only on the Google Play Store or Apple App Store. 3. **Pay Exclusively Through Official Channels**: Settle utility bills only through certified BBPS (Bharat Bill Payment System) platforms like bank apps, BHIM, PhonePe, or the utility's official SSL-secured website.

Frequently Asked Questions & Statutory Clarifications

Do electricity discoms send SMS from 10-digit mobile numbers?

Never. Official electricity distribution utilities (Tata Power, BSES, BESCOM, MSEDCL, UPPCL, WBSEDCL) send alerts exclusively via authorized 6-character sender alphanumeric IDs (e.g., TATA-P, BSES-D, MSEDCL).

What happens if I install the APK file sent on WhatsApp?

Malicious APKs install remote access trojans (RATs) that request SMS permissions, allowing attackers to intercept your bank OTPs invisibly while locking your screen.

Official Citations & Statutory References:

Advertisement

Help Protect Friends and Family

Share this threat advisory with family groups, elders, or colleagues to prevent victimization.