s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.fakecalls

📛 Threat Title

Malware family: Fakecalls

Category: Fakecalls First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.fakecalls`. Printable name: Fakecalls.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.fakecalls VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.fakecalls

IOC database

Type
domain
Value
apk.fakecalls
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.fakecalls

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.fakecalls

References (1)

Remediations (10)

  • web:arstechnica.com

    Android Trojan that intercepts voice calls to banks just got more stealthy FakeCall malware can reroute calls intended for banks to attacker-controlled numbers.

  • web:attack.mitre.org

    Fakecalls is an Android trojan, first detected in January 2021, that masquerades as South Korean banking apps. It has capabilities to intercept calls to banking institutions and even maintain realistic dialogues with the victim using pre-recorded audio snippets.

  • web:blog.checkpoint.com

    We discovered more than 2500 samples of the FakeCalls malware different in a combination of mimicked financial organizations and implemented evasion techniques. The malware developers paid special attention to the protection of their malware , implementing several unique evasion techniques that we had not seen in-the-wild before.

  • web:imtr.net

    The post Fakecalls Android Malware Abuses Legitimate Signing Key appeared first on McAfee Blog. Analysis Summary # Tool/Technique: Fakecalls Android Malware ## Overview Fakecalls is an Android banking trojan discovered in South Korea that uniquely abuses a legitimate application signing key belonging to a reputable IT services company.

  • web:rewterz.com

    Analysis Summary Researchers have found a new variant of the infamous Android malware family called FakeCall , which uses voice phishing, often known as vishing, to deceive users into disclosing personal information. FakeCall is a very advanced vishing attack that uses malware to gain almost total control over a mobile device, including the ability to intercept calls both inbound and outbound ...

  • web:thehackernews.com

    Cybersecurity researchers have discovered a new version of a well-known Android malware family dubbed FakeCall that employs voice phishing (aka vishing) techniques to trick users into parting with their personal information. " FakeCall is an extremely sophisticated Vishing attack that leverages ...

  • web:www.forbes.com

    Android users take notice. The new and improved " FakeCall " malware convincingly hijacks bank phone calls and redirects them to attackers.

  • web:www.malwarebytes.com

    Android malware FakeCall can intercept calls to the bank on infected devices and redirect the target to the criminals.

  • web:www.pcrisk.com

    What kind of malware is Fakecalls ? Fakecalls is the name of a Trojan targeting Android users. This malware imitates calls with bank employees (customer support). Fakecalls is disguised as a banking application (at least two banking apps called Kookbik Bank and KakaoBank). Cybercriminals can use Fakecalls Trojan to extract sensitive information. Fakecalls malware in detail We have found that ...

  • web:www.techradar.com

    The attack is reasonably simple: once FakeCalls is illegitimately installed on a victim's Android device, the malware operators' phone number is masked by a genuine bank number to gain trust ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
1 / 1
IPs scored
0 / 0
Flagged
1
IndicatorTypeVerdictScore
apk.fakecalls domain high 44