logo

Fakecalls Android Malware Abuses Legitimate Signing Key

ID: bc6edfd8-da67-5785-a3da-5c715759d37a

STIX ID: report--bc6edfd8-da67-5785-a3da-5c715759d37a

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2023-04-21

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research describes an Android banking trojan campaign (Fakecalls) that used a leaked legitimate signing key and packer to evade detection; the dropper installs a malicious APK disguised as an HTML asset, requests broad permissions, registers services and receivers, and connects to remote C2 infrastructure via a push SDK to exfiltrate SMS, contacts, call records, files and to control infected devices. The report includes technical details, a command list, multiple SHA256 indicators, and domains associated with the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.