You installed a fake app or APK: cleaning a compromised phone in Nepal
Installed an APK sent on Viber, WhatsApp or Messenger and now money is moving? Work the first thirty minutes in order — cut the network, freeze the money from another device, strip the permissions, then report it properly.
This guide is for the moment after the mistake. You tapped a file somebody forwarded to you on Viber, WhatsApp or Messenger — a wedding invitation, a courier tracking app, a loan approval, a Dashain reward, a traffic fine notice, an app that looked like eSewa or your bank — and your phone asked whether you wanted to install it from an unknown source, and you said yes. Now a debit has appeared that you did not make, or a friend has told you that your number is sending the same file to everybody in a group, or the phone is behaving in a way you cannot explain.
What makes this different from an ordinary OTP scam is that you did not hand anything over. Nobody phoned you and talked you into reading a code aloud. The file did the work itself. An Android app that has been granted permission to read SMS can read a one-time password the instant it arrives; an app granted an accessibility service can be told what is on the screen and can act on the screen; an app registered as a device administrator cannot be uninstalled until that registration is revoked. Put those together and the handset in your hand can be showing you a calm, ordinary home screen while approving transactions behind it.
So the order of what you do matters more than how thoroughly you do it. Cutting the phone off the network buys you the minutes you need. Freezing the money from a different device stops the bleeding. Removing the app and its permissions comes third, and a factory reset — which most advice online reaches for first — comes late, because it destroys the record of what happened along with the thing that caused it. Prevention is a separate job and the site covers it separately; this page assumes the app is already on the phone.
It also matters that you know who owns which part of the problem in Nepal, because four different bodies do. Your bank or wallet owns the money and is the only party that can attempt to hold or recall a transfer. Nepal Police's Cyber Bureau owns the crime, and its reporting page sets out exactly what a usable complaint contains. Nepal Rastra Bank owns the escalation when a licensed bank, finance company or payment provider will not deal with you, and its grievance portal will not look at a complaint you have not first put to the provider. The Nepal Telecommunications Authority owns the telecom side, including unsolicited SMS. None of them will act on a vague account of what happened, which is why the first thing this guide asks you to do is write things down.
The first five minutes: take the phone off the network, then stop using it
Turn on aeroplane mode. Then, separately, confirm that both mobile data and Wi-Fi are actually off, because on many handsets aeroplane mode leaves Wi-Fi switched on if it was on before. A hostile app needs a network to receive instructions, to forward the SMS codes it is reading and to send anything it has harvested. Taking that away does not undo what has already happened, but it converts a live incident into a static one and gives you room to think.
Do not restart the phone in the hope that it will come back clean, do not begin deleting things yet, and do not open your banking app to check the balance — each of those either destroys something you will want later or hands the app another look at a credential. The second instruction is the one people skip: do everything from here on from a different device. Borrow a family member's phone, use a laptop, walk to a relative's house. If an app on the handset holds an accessibility service, then what is on the screen and what you type into it are not private, so changing your bank password on the infected phone is worse than not changing it at all — you have handed over the new one as well.
If that phone is the household's only device and you need it to make calls, take the SIM out and put it into any basic handset. Calls to a bank helpline are the one thing you genuinely need in the next few minutes, and a feature phone with no smart apps on it will make them safely.
Now write down the facts while they are still fresh, on paper or on the clean device. What was the file called. Who sent it, on which app, and at what time. Was it forwarded from a group, and which group. What did the install prompt ask you to allow, and what did you tap. What time did you install it, and what time did you first notice something wrong. If a debit has appeared, its amount, time and transaction ID.
That note is not busywork. The Cyber Bureau's own reporting page asks a complainant for the hyperlinks and screenshots relating to the incident alongside identity documents, and a bank dispute turns on times. A complaint that says money went missing sometime last week is a complaint that goes nowhere; one that names the file, the sender, the install time and the transaction ID is something an investigator can work with.
Before you remove anything, take screenshots of it — the app's entry in the app list, its permissions screen, the chat message that delivered it. On a phone that is offline you can still screenshot freely. Those images are your evidence, and in the next hour you are going to start destroying the original.
Freeze the money from the clean device, and get a reference number
Call your bank's card and mobile-banking helpline now, from the clean device, using the number printed on the back of your debit card or shown on your bank's own website. Do not search for a helpline number and call the first result. Fraudulent 'customer care' numbers ranked into search results are a standing problem, and a person who has already installed one hostile file is exactly the person a fake helpline is waiting for.
Ask for three specific things and do not settle for a general assurance. First, block the card. Second, disable mobile banking and internet banking on the account as a channel, not merely change the password — a channel that is switched off cannot be driven by an app on your handset. Third, ask the officer to record the time of your call and give you a reference or ticket number for the block, and write that number on your paper note. That reference is the document that establishes when you notified the bank, and everything in a later dispute is measured from that moment.
Then do the wallets. Khalti publishes toll-free lines for both NTC and Ncell subscribers, a landline, WhatsApp and Viber support numbers and a support email address on its own site, along with a dispute policy — use those, not a number from a forwarded message. eSewa's official channels are reachable from its own site and blog, which also carries a piece explaining the reasons an eSewa ID gets blocked; a temporary block placed at your own request is reversible, so ask for it without hesitating.
If a transfer has already left, say so explicitly and ask the bank to raise it with the receiving institution immediately. Interbank transfers in Nepal run over connectIPS, operated by Nepal Clearing House Ltd across its member banks and financial institutions, and QR and wallet payments run over the Fonepay network, which is licensed by Nepal Rastra Bank as a payment system operator and publishes a complaint portal and a named grievance handling officer. Your own bank is the party that has to open that conversation — you cannot do it directly — but the sooner it starts, the better the chance the receiving side still holds the funds.
Do not use SMS confirmations to satisfy yourself that any of this worked. SMS is the compromised channel; an app reading and dismissing messages can hide a confirmation as easily as it hides an alert. Confirm verbally on the call, and then ask for written confirmation by email to an address you can open on the clean device.
If your phone has also stopped receiving calls and texts entirely, that is a different problem sitting on top of this one — a SIM taken over, or a service fault — and it is handled by your operator, with the Nepal Telecommunications Authority as the escalation route. Deal with it in parallel rather than assuming it is part of the same fraud, and if the handset also holds a work email or a company banking token, tell whoever runs your organisation's IT before you go any further.
What the app can actually reach, and why the screen still looked normal
The reason victims say 'but I never shared an OTP' is that on Android there are a handful of permissions which, once granted, make sharing unnecessary. Understanding which ones they are tells you what to look for and what to switch off, and it also tells you how much you have to assume was seen.
SMS access is the first. An app holding it can read every message as it arrives, including one-time passwords from your bank, your wallet and your email provider, and it can mark them read so you never see the notification. Google's Android documentation describes a permission manager — reachable through Settings, then Security and privacy, then Privacy, then Permission manager — that lets you pick a permission type such as SMS and see every app that currently holds it. That single screen is the fastest way to find out what has been reading your codes.
The second is the accessibility service. Accessibility on Android exists for genuine reasons: Google's own accessibility documentation describes services such as TalkBack, which describes your actions and tells you about alerts and notifications, and Switch Access, which lets somebody interact with the device through one or more switches. Those are powerful, and deliberately so. An app that talks a user into enabling it inherits the same reach — it can be told what is on the screen and it can drive the screen. That is the mechanism behind a phone that looks idle while a transfer is approved.
The third is device administrator registration. It is designed for corporate device management, and one of its effects is that the uninstall option for the registered app becomes unavailable until the registration is revoked. If you have tried to uninstall something and found the button greyed out, this is almost always why, and it is not a sign that the phone is beyond help.
Two more matter. Notification access lets an app read the content of notifications from other apps, which covers most of what SMS access covers and some of what an authenticator app shows. And the display-over-other-apps permission lets an app draw its own screen on top of a real one, so that what you believe is your bank's login page is a picture of it collecting your PIN.
The practical conclusion is uncomfortable but useful. Assume that anything that arrived by SMS or notification while the app was installed has been seen. That means one-time passwords, transaction alerts, and any password reset code — which is why the password changes later in this guide start with your email account rather than your bank.
iPhone users are not exempt, though iOS does not let a chat app hand you an installable package in the same way. The equivalents are a configuration profile you were asked to approve, an app delivered outside the App Store through an enterprise or testing channel, and a credential-harvesting page in Safari. Find and remove any profile you did not deliberately install; the money and reporting steps below apply unchanged.
Remove the app, and revoke the permissions that stop you removing it
Keep the phone offline while you do this, and screenshot each screen before you change it. Open Settings, then Apps, and choose the option to see all apps rather than the shortened list. Sort by install date if your handset offers it, or read the list from top to bottom looking for three things: names that imitate something real with a small difference, names that are generic to the point of meaninglessness, and entries with a blank or default icon. Anything installed within the window you wrote down is a candidate, including apps you do not remember but assume came with the phone.
Try to uninstall the suspect. If the button is greyed out, go to your handset's security settings and find the list of device administration apps — the exact wording varies by manufacturer, but it sits under Security or under a special-access section — and deactivate the entry there. The uninstall button becomes available once the registration is revoked.
Next, open Accessibility in Settings and look at the downloaded or installed services rather than the built-in ones. Turn off anything you did not deliberately enable for a real accessibility need. Then use the permission manager described above and sweep it properly: check SMS, then call logs, then phone, then notification access and the display-over-other-apps list, and remove anything that has no business holding them. A wallet does not need to read your SMS to work, and nothing you installed from a chat message needs an accessibility service.
Now run Play Protect. Google states that Play Protect checks apps from the Play Store before you download them and also checks your device for potentially harmful apps from other sources, and that when it finds one it may notify you, disable the app until you uninstall it, or remove it automatically. There is also a setting to improve harmful app detection, which sends unknown apps to Google for evaluation. Turn that on for now — the file you installed is precisely the kind of unknown app it exists to assess.
Then close the door you came in through. The permission that let a chat app install a package is granted per app, so open the special access settings for installing unknown apps and switch it off for WhatsApp, Viber, Messenger, your browser and your file manager. Leaving it on for a messaging app is the single setting that turns a forwarded file into an installed program.
Reconnect to the network only after all of that is done, and then watch the phone for a few minutes. If the app reappears, if the device-admin entry comes back, if you find a second copy under a different name, or if you cannot work out what you installed in the first place, stop cleaning and read the section on factory resets. Some families of malware install a companion that reinstalls the first, and a partial clean-up on a phone you still use for banking is worse than an honest reset.
Close the other doors it opened: forwarding rules, linked devices and accounts
Removing the app is not the end, because the point of most of these files is to leave something behind that survives the uninstall. Work through the list below from the clean device wherever the setting allows it. Start with forwarding. Open your dialler's settings and check call forwarding — an unconditional forward to a number you do not recognise means your calls, including a bank's verification callback, are going somewhere else. Then check your messaging app for any auto-forward or backup rule, and check whether your default SMS app has been changed to something you did not choose.
Then look at linked devices and active sessions everywhere that offers them. WhatsApp keeps a linked-devices list in its settings, and a device you do not recognise there has been reading your chats; log it out. Do the same in Messenger and Viber, and in any messaging app you use for anything financial.
Your Google account is the one to be most thorough with, because it is the key to the rest. Google's account documentation sets out the path: open your Google Account, go to Security and sign-in, and under Your devices choose to manage all devices, where you will see the devices currently signed in or signed in during the last few weeks. Select anything you do not recognise and sign it out. Google's guidance is explicit that you should sign out on devices that are lost, that you no longer own, or that do not belong to you.
In the same account, review third-party access. Google documents a separate screen listing the apps and services granted access to your account data, with a details view and a remove-access control; it notes that removing access may make some features of that app unavailable, which is the correct trade here. Anything you do not recognise should lose its access now.
Only now change passwords, and change them in this order: email first, then your bank and wallets, then social media, then anything that reuses the old password. Email comes first because whoever holds your email can reset almost everything else. Do this from the clean device, and where a service offers two-factor authentication through an authenticator app rather than SMS, take it — on a handset whose SMS may have been read, a code app is the stronger choice.
Finally, tell people. Many of these files spread by harvesting the contact list and sending themselves onward under the name of somebody the recipient trusts, which is why the message arrived from a friend rather than a stranger in the first place. A short message to your Viber and Messenger groups saying that anything sent from your number in the last day should be deleted rather than opened will stop the chain, and it costs you nothing but a moment of embarrassment.
Factory reset: when it is genuinely necessary, and what it costs you
A factory reset is the reliable answer and the expensive one. It is necessary when the app cannot be uninstalled even after revoking device administration, when it reappears after removal, when you cannot identify what you installed, when the phone continues to behave oddly after a clean sweep, or when the amount of money involved means you cannot afford to be ninety per cent sure. It is not necessary the moment you realise you tapped a file, and doing it in the first five minutes is a mistake.
The reason is evidence. Google's documentation is plain that a reset removes all data from the phone and that all apps and their data are uninstalled. That includes the malicious package itself, its permission record, the notification and SMS history around the fraudulent transactions, and the chat thread that delivered the file if that app's data is not backed up. A bank investigating a disputed debit and a Cyber Bureau investigator opening a complaint both work from that material. Screenshot everything described in the previous sections first, and email the screenshots to yourself so they exist somewhere other than the phone you are about to wipe.
Prepare properly. Google's guidance asks you to know your Google account username and password and your screen lock before you start, to charge the device to at least seventy per cent, to be connected to Wi-Fi or a mobile network, and to expect the process to take up to an hour. Data held in your Google account can be restored afterwards. Where a handset supports storing transit cards or similar balances in a wallet app, those need handling before the reset rather than after.
There is a trap in the restore. A backup taken after the infection can contain the thing you are trying to remove, so when the phone asks whether to restore apps, decline. Bring back contacts, photos and documents selectively, and reinstall each app you actually use by hand from the Play Store or App Store. It is slower and it is the whole point of the exercise.
Change your Google account password from the clean device before you sign back in on the reset handset, not after. Signing a freshly wiped phone into an account whose password may already be known reopens the door before you have shut it. Re-enrol two-factor authentication at the same time, and check the manage-devices list once more afterwards so the reset device is the only entry you recognise.
Leave your banking and wallet apps until last, and reinstall them only once your bank has confirmed that the channel it disabled has been re-enabled with fresh credentials. There is no urgency here that outweighs getting it right; a few days of paying cash is a smaller loss than the first one. One judgement is worth making at the same time: if the handset is old enough that it no longer receives security updates from its manufacturer, a reset returns it to a state that was already vulnerable, which is a reason to plan a replacement rather than assume the problem is closed.
Reporting it: the bank dispute, the Cyber Bureau, and NRB when the bank stalls
Put your dispute to the bank in writing on the same day you telephoned, and hand it in at the branch so you have a receipt. Include your account or wallet identifier, each disputed transaction with its amount, date, time and transaction ID, the time you called the helpline and the reference number you were given for the block, a plain statement that you did not authorise or approve the transactions, and a short account of the installed file. Ask for a written acknowledgement with a complaint number. Verbal complaints leave no trace and are the reason so many of these cases stall.
Then report the crime. Nepal Police's Cyber Bureau sets out on its reporting page what a complaint needs: the complainant's citizenship certificate, national identity card or passport, and the relevant hyperlinks and screenshots. It publishes downloadable complaint forms for specific categories, including one for online financial fraud, which is the right form here. Complaints can be lodged at the nearest district police office or local police station, or at the Bureau's own office, and complete details can also be sent by email to [email protected]. The Bureau lists its contact numbers as 01-5319044 and 9851286770, and its office at Bhotahity in Kathmandu.
If you are outside the Kathmandu Valley, do not wait for a trip to the capital. Nepal Police maintains district police offices across all seven provinces — Koshi, Madhesh, Bagmati, Gandaki, Lumbini, Karnali and Sudurpashchim — and publishes the police control number 100 along with a toll-free line, 16600141516. Filing locally starts the clock, and the file can be moved.
Escalate to Nepal Rastra Bank only after the provider has had its chance. NRB's financial consumer protection grievance portal states the sequence directly: lodge the grievance with the financial service provider first, and come to NRB if the provider fails to address it or the outcome is unsatisfactory. It issues a registration number by email when a complaint is filed. It also states what it will not take — submissions with incorrect contact details, unclear or incomplete information, matters already before a court or in arbitration, complaints about institutions that do not hold NRB authorisation, and abusive submissions.
That authorisation point decides whether this route is open to you at all. NRB's Payment Systems Department licenses payment system operators and payment service providers and supervises them, so a licensed wallet or bank is inside the perimeter. A 'loan app' that appeared in a chat message and is not licensed by anyone is not, and for that you are relying on the police rather than the regulator. It is also worth knowing that banks and payment providers report suspicious transactions to NRB's Financial Information Unit, which is the central point of Nepal's anti-money-laundering regime and receives suspicious transaction and activity reports from them — that reporting obligation is part of why your bank will ask you a great many questions rather than none.
If the abuse also ran through your phone line — unsolicited SMS from unknown numbers asking for personal details, charges you did not authorise, a service you never subscribed to — the Nepal Telecommunications Authority operates a grievance management system, reachable from its own site, and has issued public notices about exactly that kind of SMS. Complain to the operator first, keep the complaint number, then escalate.
Use the payment providers' own dispute machinery in parallel, because it is often faster than anything else. Fonepay publishes a complaint portal and names a grievance handling officer with a direct contact; Khalti publishes support lines, a support email and a dispute policy; connectIPS transactions are settled through Nepal Clearing House Ltd, and your bank is the party that raises a case there. Log each of these with a reference and keep every reference in one place.
Be realistic about the outcome, because false hope wastes effort. A transfer caught while the funds are still sitting in the receiving account has a real chance. Money that has been moved onward through several accounts, converted at an agent or withdrawn in cash is a police matter rather than a refund matter, and police matters in cybercrime take months rather than days. That is an argument for speed in the first hour, not an argument for giving up.
Telling the genuine eSewa, Khalti or bank app from the clone you were sent
Once the phone is clean, the last job is making sure you never repeat the install. The rule that does most of the work is short: an app that matters arrives from the Play Store or the App Store, and you reach that store listing from the company's own website rather than from a search result, an advertisement or a forwarded link.
That is checkable. Khalti's own site carries App Store and Google Play badges as its stated download route, and eSewa's blog carries the same badges alongside its published support channels. If you open the company's site, tap its badge and land on the store listing, you have removed the entire class of attack that this guide is about. If somebody sends you a file instead, you already know what it is.
On the store listing, read three fields before you install. The developer name should be the company itself, not a personal name or a slight variation. The install count for a Nepali wallet or a commercial bank should be in the millions or the hundreds of thousands, not the hundreds. And the update history should show recent, regular releases. A near-duplicate listing with a similar icon, a lower install count and a first release last month is a clone.
A licensed payment provider in Nepal does not distribute its app as an APK in a chat message, and neither does a bank. Nepal Rastra Bank's Payment Systems Department licenses payment system operators and service providers and issues unified directives to them; distribution through Viber forwards is not how any of that works. Treat an APK arriving in chat as fraudulent by definition, no matter who appears to have sent it, because the sender's account is frequently a previous victim's.
Keep the install-unknown-apps permission switched off for every messaging app and browser permanently, and leave Play Protect enabled. Watch what an installer asks for, because the request itself is the tell. A wallet needs a network connection and, if you use QR, a camera. It does not need an accessibility service, it does not need device administrator rights, and it does not need to become your default SMS app. If an install prompts for any of those three, stop at that screen — that is the exact moment at which the harm in this guide becomes possible, and it is the last moment at which it costs you nothing to walk away.
Finally, be sceptical of lending apps in particular, because they are the category that most often combines a plausible pitch with permissions no lender needs. Before you install one, ask whether the lender is a bank, a finance company or a payment provider licensed by Nepal Rastra Bank. If it is not, then NRB's grievance route is closed to you by its own published rules when things go wrong, and you will be left with a police complaint and a phone full of your own contacts in somebody else's hands.
Key takeaways
- ✓Put the phone into aeroplane mode and confirm Wi-Fi is off, then do everything else from a different device — an app holding an accessibility service can read the screen you are typing into.
- ✓Call your bank from the clean device, ask for the card blocked and mobile banking disabled as a channel, and get a reference number and the time of the call recorded.
- ✓Check SMS access, notification access, accessibility services, device administrator registration and display-over-other-apps; device-admin registration is why an uninstall button is greyed out.
- ✓Factory reset only when cleaning fails or you cannot identify what you installed, and screenshot everything first — Google's own documentation confirms a reset uninstalls all apps and their data.
- ✓Report to the Cyber Bureau with citizenship or passport, screenshots and links, complain to your bank in writing the same day, and take it to Nepal Rastra Bank's grievance portal only after the provider has failed you.
Explore the data behind this guide
You Installed a Fake App or APK — FAQ
I installed an APK but no money has gone yet. Do I still need to do all this?+
Yes, and quickly. The gap between installation and the first transaction is often hours or days while the app waits for a code it can use. Cut the network, work through the permission checks, remove the app and change your email and banking passwords from another device. Tell your bank what happened even if nothing is missing — it can watch the account.
Why should I not change my bank password on the phone itself?+
Because if a hostile app holds an accessibility service or an overlay permission, what appears on the screen and what you type into it are visible to it. Changing a password on a compromised handset hands over the new password as well. Change passwords from a laptop or a family member's phone, starting with your email account, which can reset everything else.
The uninstall button for the app is greyed out. What do I do?+
That is almost always device administrator registration, which is a legitimate Android feature for corporate device management that also blocks removal. Open your handset's security or special access settings, find the device administration apps list, deactivate the entry for the app, then uninstall it normally. Take a screenshot of the entry before you deactivate it, because it is evidence.
Is a factory reset always the safest option?+
It is the most thorough option, but it erases the evidence a bank dispute and a police complaint both need. Google's documentation confirms a reset uninstalls all apps and their data. Screenshot the app, its permissions and the message that delivered it first, email those to yourself, and decline the offer to restore apps afterwards, since a backup taken after the infection can bring the app back.
Where exactly do I report this in Nepal, and what do I need to bring?+
The Nepal Police Cyber Bureau's reporting page asks for the complainant's citizenship certificate, national identity card or passport, plus the relevant links and screenshots, and offers a specific form for online financial fraud. You can file at the nearest district police office or local police station, at the Bureau's office in Kathmandu, or by email to [email protected].
My bank is refusing to investigate. Can Nepal Rastra Bank make it?+
NRB's financial consumer protection grievance portal takes complaints about licensed institutions, but only after you have raised the matter with the provider and it has failed to resolve it. It issues a registration number by email. It will reject incomplete or unclear submissions, anything already in court or arbitration, and complaints about institutions that hold no NRB authorisation.
Can the fake app have sent itself to my friends?+
Yes, and that is how most of these files circulate. Harvesting the contact list and forwarding the same package under a trusted name is exactly why the message reached you from somebody you know. Post a short warning to your Viber and Messenger groups telling people to delete rather than open anything sent from your number during the incident window.
I have an iPhone. Am I safe from this?+
Safer, but not exempt. iOS does not let a chat app hand you an installable package the same way, so the equivalents are a configuration profile you were asked to approve, an app delivered outside the App Store through an enterprise or testing channel, and a credential-harvesting page in Safari. Remove any profile you did not deliberately install, then follow the same money and reporting steps.
Related guides
Sources & data note
The procedural facts are lifted from the bodies named in the text: the Cyber Bureau's reporting page for what a complaint must contain and where to file it; Nepal Rastra Bank's grievance portal for the complain-to-the-provider-first rule and its exclusions; NRB's Payment Systems Department for what a licensed wallet is; the Nepal Telecommunications Authority for its grievance route and SMS advisories; and Google's documentation for Play Protect, permissions, device sign-out and factory resets. The ordering of the first thirty minutes, the judgement that the recorded time of your call decides a later dispute, the reading that a device-admin or accessibility grant explains a screen that looks normal, and the assessment that money moved onward is rarely recovered are our own analysis; the cited sources do not draw those conclusions, and menu wording differs by handset. Helpline numbers, toll-free lines and complaint categories change — confirm with your bank, the Cyber Bureau on 01-5319044 and NRB before acting. Guides are written from primary sources — Nepali government departments, operators, park authorities and standards bodies — and each guide lists the sources used for its own facts. Rules, fees and prices in Nepal change; treat figures as current at the review date shown on each guide and verify anything money- or visa-critical with the issuing authority before you rely on it.
- Nepal Police Cyber Bureau — official site, role and contactsNepal Police ↗
- Cyber Bureau — report a cyber crimeNepal Police ↗
- Nepal Police — national portal, complaints and district officesNepal Police ↗
- NRB Grievance Management System — financial consumer protection portalNepal Rastra Bank ↗
- Nepal Rastra Bank — central bank homepage and consumer protection portal linkNepal Rastra Bank ↗
- NRB Payment Systems Department — licensing and supervision of PSOs and PSPsNepal Rastra Bank ↗
- Financial Information Unit — Nepal's anti-money-laundering focal pointNepal Rastra Bank ↗
- Nepal Telecommunications Authority — official site, grievance system and public noticesNepal Telecommunications Authority ↗
- NTA Complaint Handling SystemNepal Telecommunications Authority ↗
- Khalti — official site, app download route and support channelsKhalti ↗
- eSewa blog — official app download badges and security postseSewa ↗
- Fonepay — QR and payment network, complaint portal and grievance officerFonepay ↗
- connectIPS — interbank payment platformNepal Clearing House Ltd ↗
- Google Play Protect — how it scans apps and devicesGoogle ↗
- Change app permissions on your Android phoneGoogle ↗
- Android accessibility overviewGoogle ↗
- See devices with account access and sign outGoogle ↗
- Third-party apps and services with access to your accountGoogle ↗
- Reset your Android device to factory settingsGoogle ↗
- NPCERT — Information Security Response Team NepalNPCERT ↗
- Nepal Law Commission — full text of Nepali ActsNepal Law Commission ↗