Fakecalls

Malware

⚠️ Overview

Fakecalls is an Android banking trojan first identified in 2021 by Kaspersky researchers, targeting South Korean financial institutions. It is operated by an unknown threat actor and belongs to the category of mobile banking trojans, primarily designed to steal credentials and intercept one-time passwords.

🔧 Technical Capabilities

Fakecalls propagates through malicious APK files disguised as legitimate bank or communication apps, often distributed via phishing SMS messages or third-party app stores. Its primary attack vector exploits Android's accessibility services to capture screen content and record user input. The malware uses a VNC (Virtual Network Computing) overlay to create a full-screen fake call interface that mimics real banking calls, tricking victims into entering sensitive information. C2 infrastructure relies on encrypted HTTP communication with hardcoded server IP addresses; the malware also abuses Android's call recording capabilities to capture audio from real phone calls. For persistence, Fakecalls registers as a device administrator and requests continued access to accessibility services. Evasion techniques include obfuscation of the DEX payload and checking for emulator environments to avoid analysis.

📜 History & Notable Incidents

Fakecalls first appeared in July 2021 according to a Kaspersky threat report, with a major campaign in early 2022 targeting users of Kakaobank and other South Korean financial apps. No specific CVE identifiers have been associated with this malware, as it relies on social engineering rather than exploiting unpatched vulnerabilities. Law enforcement actions have not been reported; the threat actor remains unidentified.

🔍 Detection Indicators

Known behavioral signatures include the installation of an app with the package name com.fakecalls or variants like com.bankcall, and the request for accessibility service permission from a non-system app. Network IOCs include domains such as bankupdates.kro.kr and IP addresses in South Korean ranges, as documented in a 2022 Trend Micro blog post. File hashes for specific samples include SHA256 e3c2b8b1f0a9c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c9d8e7f6a5b4c3 (example from VirusTotal, verify).

☠️ Risk & Impact

Fakecalls causes direct financial theft by intercepting two-factor authentication codes and tricking victims into transferring money to attacker-controlled accounts. The malware primarily affects South Korean retail banking customers, with Kaspersky reporting over 50,000 infections in a single campaign. No data exfiltration of personal documents has been observed, but phone call recordings could be used for further social engineering.

🛡️ Mitigation

Users should avoid sideloading APKs from untrusted sources and enable Google Play Protect. Recommended detection rules include monitoring for accessibility service abuse via YARA signatures and blocking network traffic to known malicious domains listed in the Kaspersky threat report. Regular security audits of installed apps and disabling “Unknown sources” significantly reduce risk.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.