Fake Banking App Found on Google Play Used in SMiShing
ID: 9871d804-0ffe-59f5-be9a-5d6ed5360011
STIX ID: report--9871d804-0ffe-59f5-be9a-5d6ed5360011
Feed Name: TrendAI Security Blog
A malicious Android spyware family (AndroidOS_FlokiSpy.HRX) masqueraded as legitimate mobile token apps for Spanish banks (including BBVA), was published on Google Play, and collected device identifiers and SMS messages before exfiltrating them to a command-and-control server (https://backup.spykey-floki.org/add.php). The report documents multiple related apps from the same developer, includes four sample hashes, screenshots of C2 and client behavior, and warns the stolen SMS content is being used for SMiShing and banking fraud; Google removed the apps after discovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
