HARI Raya is a time for open houses, warm greetings and rendang that disappears far too quickly.
But scammers have apparently decided to get in on the festive spirit, this time hiding dangerous software inside what appears to be a harmless digital invitation card.
Are fraudsters really disguising malicious APK files as Hari Raya open house invitations?
Verdict:

TRUE
Scammers are circulating fake Hari Raya open house invitations via WhatsApp and Telegram that conceal dangerous APK files capable of compromising victims' phones and draining their bank accounts, according to a warning issued by the Selangor Commercial Crime Investigation Department (CCID) and reposted by the South Klang District Police.
An APK file is a type of application installation file used on Android devices, and is not a standard format for digital invitations of any kind.
The scam works by sending targets a message purporting to be an open house invitation, accompanied by a link to download what is presented as a digital invitation card but is in fact a malicious APK file.
In some variations of the scam, the link instead directs victims to a fake website designed to harvest personal information.
Once the APK file is downloaded and installed, the victim's phone is immediately compromised, giving scammers access to SMS messages, bank one-time passwords (OTPs) and other important applications.
To make the messages appear legitimate, scammers typically use the names of acquaintances or VIP figures, craft enticing phrases such as "exclusive invitation," include actual Hari Raya dates to appear realistic and pressure victims into opening or clicking the link immediately.
The police stressed that legitimate open house invitations are typically shared as image files in JPEG or PNG format, or as physical cards, and never as APK files.
They advised the public to not to click on suspicious links, not to install APK files from unknown sources, to verify any invitation by calling the host directly if in doubt, to download applications only through the Google Play Store and to ensure their phone's security settings are activated.
Reference:
1. https://www.facebook.com/reel/
