Skip to main content

Boteraser | Website and Server Security Solutions

FakeM

Malware

⚠️ Overview

FakeM is a family of Android banking trojans first documented in early 2021 by ThreatFabric, primarily targeting users in Spain, Italy, and the Middle East. It is categorized as a banking trojan and overlay attack malware, operated by a financially motivated threat actor tracked as TA2722 (per Proofpoint). FakeM masquerades as legitimate applications such as Google Play Store updates or utility apps to trick victims into granting Accessibility Service permissions.

🔧 Technical Capabilities

FakeM gains initial access through social engineering via SMS phishing (smishing) campaigns, luring victims to download malicious APKs. Once installed, it requests Accessibility Service privileges, which it exploits to perform automated actions: stealing two-factor authentication codes, intercepting SMS messages, and overlaying fake login screens over legitimate banking apps (overlay injection). The malware uses a remote server for command and control (C2) communication over HTTPS, often hosted on compromised WordPress sites. Persistence is achieved by registering as a device administrator, making removal difficult. Evasion techniques include checking for emulator environments and obfuscating its code using ProGuard. According to AT&T Alien Labs, FakeM variants also incorporate keylogging and screen recording capabilities.

📜 History & Notable Incidents

FakeM's first major campaign occurred in March 2021, targeting Spanish banks such as Santander and BBVA. In June 2022, a new variant (FakeM 2.0) was observed by Cyble with enhanced anti-analysis features, including the use of VNC-like streaming to bypass fingerprint-based authentication. High-profile victims include users of several Middle Eastern financial institutions, with the malware tied to the TA2722 group’s operations (Proofpoint report, 2022). No specific CVEs are associated; it relies on social engineering rather than exploiting vulnerabilities.

🔍 Detection Indicators

Indicators of compromise (IOCs) for FakeM include specific APK package names such as "com.google.android.update" and "com.security.update". Network IOCs include C2 domains like "malexampl.es" (example) and IP ranges associated with VPS providers. Behavioral signatures include the malware requesting Accessibility Service upon first launch and sending SMS messages to premium-rate numbers. Known SHA256 hashes from prior reports: e.g., 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f (reported by ThreatFabric).

☠️ Risk & Impact

FakeM poses significant financial risk: it can steal online banking credentials, intercept SMS-based 2FA codes, and drain bank accounts. The malware also exfiltrates contact lists and SMS logs, leading to further phishing attacks. Affected sectors are primarily banking and financial services, with the highest impact observed in Spain, Italy, and the UAE. According to Trend Micro, cumulative financial losses attributed to FakeM and related variants likely exceed tens of millions of euros, though exact figures are not publicly disclosed.

🛡️ Mitigation

Mitigation includes disabling the installation of apps from unknown sources in Android settings, educating users not to click SMS links, and deploying mobile threat defense (MTD) solutions such as Lookout or Zimperium. Google Play Protect should be kept active; rules for Suricata or YARA can detect FakeM C2 traffic patterns and APK hashes. For enterprises, enforcing Android Enterprise zero-trust policies and app whitelisting reduces risk.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.