The National Bank of Tajikistan (NBT) has warned citizens about malicious APK files being distributed through Telegram, WhatsApp and other communication channels.
According to the national financial regulator, the files may be disguised as banking applications, documents, receipts, wedding invitations, photographs or other seemingly legitimate content. The National Bank said in a warning
Installing such files can give fraudsters access to a user’s mobile device, personal information, SMS messages, banking applications and electronic wallets, potentially resulting in financial losses.
The National Bank advised citizens to:
- avoid downloading or installing APK files from unknown or unverified sources;
- avoid clicking on suspicious links received through messaging apps, SMS or email;
- never share PINs, passwords or one-time confirmation codes with anyone;
- verify the source of any message or file, even if it appears to come from a friend, bank, government agency or other trusted organization.
The regulator stressed that employees of banks and other credit and financial institutions do not ask customers for PINs, passwords or one-time confirmation codes and do not instruct them to install third-party or unofficial applications.
What to do if a suspicious file has been installed
Anyone who has already installed a suspicious APK file, or suspects that their banking information has been accessed without authorization, should contact their bank or other relevant financial institution immediately.
The Communications Service of Tajikistan has previously issued a similar warning about the distribution of malicious APK files. Asia-Plus report on the Communications Service warning
The communications service agency urged Telegram and WhatsApp users not to download, open or install APK files received from unknown sources.
Other Tajik authorities have also warned about the risks of malicious files being used to steal personal and banking information.











