Skip to content
THE TECHLEEZ / INDIA-FIRST DIGITAL INTELLIGENCE Monday, 24 August 2026
The Signal AIUPISmartphonesStartupsStreamingTravel TechEsports
Online Tips

Fake APK Scams on WhatsApp: How the Wedding Invite Fraud Works

The invitation arrives as a file, not a picture. One Android setting shuts the entire attack down before it starts - and most people have never touched it.

The wedding invitation arrives on WhatsApp as a file, not a picture. It is named something like Wedding_Invitation_Sharma.apk, and the moment you tap install, you have handed a stranger your phone.

This single scam pattern has cost Indians a great deal of money, and it works because a wedding invitation from an unknown number is completely unremarkable in India. Here is how it operates and how to shut it down.

Why an APK Is Different From an Image

An APK is an Android application installer. Opening one does not display anything — it installs software.

A genuine invitation arrives as a JPEG, a PDF or a video. No legitimate invitation, bill, court notice, delivery update or bank document is ever an APK. There is no exception to this. If the file ends in .apk, the sender wants software on your phone.

The variants change with the season: wedding invitations, festival greetings, electricity bill warnings, courier delivery updates, EPFO or PF alerts, fake banking apps, traffic challan notices. The wrapper is different; the payload is the same.

What the App Does Once Installed

The installer asks for permissions that sound routine and are catastrophic in combination:

  • SMS access — it now reads every OTP that arrives, silently
  • Contacts — your entire address book is uploaded, and the same message goes out to them appearing to come from you
  • Accessibility services — the most dangerous of all, allowing it to read what is on your screen and to tap on your behalf
  • Notification access — every alert, including banking
  • Storage — photographs and documents, including the Aadhaar and PAN scans most people keep on their phone

With SMS and accessibility together, an attacker can open your banking app, read the balance, initiate a transfer and approve the OTP without you seeing anything. People discover it when the money is already gone.

The contacts theft is what makes it spread. Your friends receive the same file from your number, which is far more convincing than from a stranger.

The Rule That Prevents All of It

One rule, no exceptions: never install an APK received through a message.

Not from WhatsApp, not from Telegram, not from SMS, not from email. Not even from a number you know, because a known number may already be compromised.

Every legitimate Android app comes from the Play Store. If someone insists their app is only available as a direct download, that is a reason for suspicion rather than an explanation. There are narrow legitimate cases for sideloading, and the precautions are in our guide to installing APK files safely — but a file that arrived unsolicited in a chat is never one of them.

Turn Off the Setting That Allows It

Android will not install an APK unless you have permitted the source app to do so, and this permission is granted per app.

Go to Settings → Apps → Special app access → Install unknown apps. Go through the list and turn this off for WhatsApp, Telegram, your browser, your file manager and anything else that does not need it.

This is a two-minute change that makes the entire attack fail at the first step, even if someone in your household taps the file. Do it on your parents’ phones as well.

If You Have Already Installed One

Act in this order, quickly.

  1. Turn on airplane mode. This cuts the app off from the network immediately and stops data leaving while you work.
  2. Uninstall the app. If it will not uninstall, boot into safe mode — usually by long-pressing the power-off option — which disables third-party apps, and remove it there.
  3. Revoke accessibility access under Settings → Accessibility if the app appears there. Some malware blocks uninstallation until this is removed.
  4. Call your bank and freeze net banking, cards and UPI.
  5. Call 1930 if any money has moved, and file on cybercrime.gov.in.
  6. Change passwords from a different device, starting with email.
  7. Warn your contacts that messages from your number may not be from you.
  8. Consider a factory reset. For anything that had accessibility access, this is the only way to be confident it is gone.

The recovery sequence for lost money is the same as for any payment fraud — see our guide to UPI fraud and recovery.

Tell the People Who Will Fall for It

The technically confident are not the target. Parents, grandparents and anyone who receives a lot of forwards are.

Give them one sentence rather than a lecture: never tap a file in WhatsApp that does not open as a picture straight away. That single instruction covers the whole category without requiring them to know what an APK is.

Then turn off install-from-unknown-sources on their phone yourself, so the rule has a backstop.

Report the message through the Chakshu module on Sanchar Saathi so the number gets blocked — see our Sanchar Saathi guide. We publish practical Indian security guidance at Techleez com.

Why This Works So Well in India

The scam is not sophisticated. Its effectiveness comes from context.

Indian phones receive a constant stream of forwarded files from numbers not in the address book — wedding cards, festival greetings, notices, circulars, photographs from a group. A file from an unknown number is not remarkable here in the way it would be elsewhere, so the usual instinct to question it never fires.

The wrappers are chosen to match the moment. Wedding season brings invitations. Festival weeks bring greetings. Bill cycles bring electricity warnings and disconnection notices. Around results season it becomes admit cards and scholarship forms. The pattern is always the same file type with a different story attached.

Teach the File Type, Not the Story

Chasing individual scam stories is unwinnable, because a new one appears every month. Teaching the file type is permanent.

An image opens instantly and shows a picture. A PDF opens and shows a document. An APK asks permission to install something. That third behaviour is the only signal anyone needs, and it does not change when the story does.

If someone in your family is unsure, give them a fallback that requires no judgement: forward the file to you before opening anything. It costs you a few seconds a month and removes the decision from the person least equipped to make it.

Frequently Asked Questions

What is an APK scam?

A fraud where an Android installer file is sent through WhatsApp disguised as an invitation, bill or notice. Installing it gives the attacker access to your SMS, contacts and screen.

Can a legitimate invitation be an APK?

No. Genuine invitations, bills and notices arrive as images, PDFs or videos. An APK is software, never a document.

How do I stop APKs installing from WhatsApp?

Settings → Apps → Special app access → Install unknown apps, and turn it off for WhatsApp, Telegram, your browser and your file manager.

What if the file came from someone I know?

Their phone may be compromised and sending it automatically. Do not install it, and tell them.

I installed one. What do I do first?

Airplane mode immediately, then uninstall, then call your bank, then 1930 if money moved.

Is a factory reset necessary?

If the app had accessibility access, yes. That is the only way to be confident nothing remains.

About the author

Fold Smith

Fold Smith is a technology journalist and the lead editor of The Techleez, an India-first publication that decodes technology, digital payments, streaming and online culture for everyday readers. From UPI and fintech explainers to OTT streaming guides, Android tips and online-safety checklists, he personally tests the apps, tools and services featured on the site before recommending them. His focus is practical, research-backed guidance that helps Indian readers make smarter digital decisions — spend less, stream better and stay safe online. When he is not writing, he is usually tracking NPCI circulars, first-day-first-show box office numbers, or the next big OTT premiere.

More from this author →