FakeGram is an Android banking trojan first documented by Cleafy in August 2022, attributed to a threat actor tracked as Team Universe, who operates it as a malware-as-a-service (MaaS) targeting Brazilian financial institutions. It falls under the categories of credential stealer and overlay attack malware, leveraging fake login screens to intercept two-factor authentication (2FA) codes and credentials.
FakeGram abuses Android’s Accessibility Service to perform overlay attacks on over 50 Brazilian banking apps, capturing credentials, SMS messages, and push notification content. It employs a C2 infrastructure using Firebase Cloud Messaging (FCM) for command delivery and WebSocket channels for exfiltration, enabling real-time theft of OTP codes. Persistence is achieved through device administrator abuse and hiding its icon after installation. Evasion techniques include checking for debugger presence, emulator detection, and dynamic code loading via DEX files. Propagation occurs primarily through phishing SMS messages with shortened URLs hosting the malicious APK.
First observed in July 2022 by Cleafy, FakeGram was linked to campaigns targeting Brazil’s largest banks, including Banco do Brasil, Itaú, and Caixa Econômica Federal. In September 2022, a new variant added support for intercepting WhatsApp messages to bypass 2FA. No specific CVEs have been assigned, as the malware relies on social engineering and Accessibility Service abuse rather than unpatched vulnerabilities.
Indicators include package names like com.app.insta and com.seguranca.atualizacao; network IOCs include C2 domains such as fireio[.]xyz and sparkcloud[.]xyz. The malware creates a mutex named GlobalAppDeviceAdminLock and registers a device admin receiver titled DeviceAdmin. Behavioral signatures involve overlay views appearing on top of legitimate banking apps and persistent background service requests for Accessibility permissions.
FakeGram directly causes financial losses through unauthorized wire transfers and credit card fraud, with Cleafy estimating a daily attempt rate of over 1,000 infections during peak campaigns in Brazil. The malware primarily targets the fintech and retail banking sectors, compromising mobile users' credentials and 2FA tokens, leading to account takeovers and fund theft.
Users should enable Google Play Protect and avoid installing APKs from untrusted sources; enterprises can deploy mobile threat defense (MTD) solutions like Lookout or Zimperium with detection rules for overlay attacks and Accessibility Service abuse. Install apps only from the official Google Play Store and review app permissions that request Accessibility Service access unnecessarily.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.