NexusRoute is an Android-focused malware operation targeting users in India through phishing portals that impersonate Indian government services and redirect victims to malicious APKs hosted on public code-sharing infrastructure. The malware is used to harvest personal and financial information and has been associated with theft of mobile numbers, vehicle-related data, UPI PINs, one-time passwords, and payment card details. Reported functionality also includes extensive device surveillance, indicating a broader post-compromise collection capability beyond simple credential harvesting. NexusRoute appears to be part of a broader underground Android malware development ecosystem and reflects professionally engineered mobile threat activity centered on social-engineering-driven initial access and financial data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities. (Note: 'NexusRoute' also appears as malware elsewhere in the same aggregated list.)
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity; also appears as a malware name elsewhere in the content, but here is explicitly listed under Threat Actors.
NexusRoute is a professionally engineered Android malware campaign targeting users in India, combining phishing, malware, financial fraud, and surveillance, and leveraging government branding and automated infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.