logo

Fake Banking App Found on Google Play Used in SMiShing

ID: 9871d804-0ffe-59f5-be9a-5d6ed5360011

STIX ID: report--9871d804-0ffe-59f5-be9a-5d6ed5360011

Feed Name: TrendAI Security Blog

Threat Score
65/100

Date Published: 2026-01-01

Date Updated: 2026-08-06

...
...

A malicious Android spyware family (AndroidOS_FlokiSpy.HRX) masqueraded as legitimate mobile token apps for Spanish banks (including BBVA), was published on Google Play, and collected device identifiers and SMS messages before exfiltrating them to a command-and-control server (https://backup.spykey-floki.org/add.php). The report documents multiple related apps from the same developer, includes four sample hashes, screenshots of C2 and client behavior, and warns the stolen SMS content is being used for SMiShing and banking fraud; Google removed the apps after discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.