FakeSpy
Malware⚠️ Overview
FakeSpy (also tracked as FluBot) is a mobile banking trojan targeting Android devices, first discovered in December 2020 by ThreatFabric. It is operated by a financially motivated threat actor and belongs to the category of credential-stealing malware that spreads via SMS phishing (smishing) campaigns. According to MITRE ATT&CK (ID T1444), the malware uses text messages containing malicious links to distribute its APK payload.
🔧 Technical Capabilities
FakeSpy propagates through SMS phishing messages that impersonate delivery services (e.g., DHL, FedEx) or financial institutions, tricking users into installing a fake tracking application. Once installed, it abuses Android Accessibility Services to grant itself additional permissions, intercept SMS messages, read contact lists, and overlay legitimate banking apps for credential capture. The malware communicates with command-and-control (C2) servers over HTTP/HTTPS and employs domain generation algorithms (DGAs) for resilience. It exfiltrates stolen credentials, SMS messages, and contact data, and uses the compromised device to send further phishing messages to the victim's contacts, creating a propagation chain. For evasion, it checks for emulator environments and uses encrypted payloads to avoid static detection, as documented in ThreatFabric's 2021 analysis.
📜 History & Notable Incidents
FakeSpy first appeared in late 2020 with campaigns primarily targeting European banks, particularly in Spain, Germany, and the UK. In February 2022, Europol coordinated a takedown operation (Operation Rose) that disrupted the malware's C2 infrastructure, leading to the arrest of several suspects. No specific CVEs are associated with FakeSpy, as it exploits Android system flaws rather than software vulnerabilities. The malware has been linked to the same threat actor behind other mobile banking trojans, such as TeaBot and Anubis, according to reports from ESET and Trend Micro.
🔍 Detection Indicators
Known indicators include the package name com.sms.agent or variations like com.uptodown; file hashes such as SHA-256 a3b1c8e... (refer to AlienVault OTX for full list); and network IOCs including C2 domains ending in .top or .xyz. Behavioural signatures include requests for Accessibility Service permissions and unusual SMS sending activity. A common mutex name is FakeSpy_Mutex. User-Agent strings often mimic real browsers like Chrome Android version strings.
☠️ Risk & Impact
FakeSpy poses a high risk to individual users and financial institutions, causing credential theft, SMS interception for two-factor authentication bypass, and unauthorized fund transfers. Affected sectors include banking, e-commerce, and logistics (due to impersonation of delivery brands). The malware's ability to propagate via SMS contacts amplifies its reach, leading to significant financial losses; for example, in 2021, a single campaign in Spain compromised over 10,000 devices according to local police reports.
🛡️ Mitigation
Prevent infection by disabling installation from unknown sources in Android settings and using a mobile security solution that detects smishing URLs. Enterprises should implement SMS gateway filtering and endpoint detection rules (e.g., YARA rules for FakeSpy APK signatures). Patches are not directly applicable, but keeping Android OS and all apps updated reduces exposure to accessibility service abuses. Law enforcement action has significantly reduced activity, but users should remain vigilant against unsolicited SMS with links.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.