Fakecalls Android Malware Abuses Legitimate Signing Key
ID: bc6edfd8-da67-5785-a3da-5c715759d37a
STIX ID: report--bc6edfd8-da67-5785-a3da-5c715759d37a
Feed Name: McAfee Labs Blog
McAfee Mobile Research describes an Android banking trojan campaign (Fakecalls) that used a leaked legitimate signing key and packer to evade detection; the dropper installs a malicious APK disguised as an HTML asset, requests broad permissions, registers services and receivers, and connects to remote C2 infrastructure via a push SDK to exfiltrate SMS, contacts, call records, files and to control infected devices. The report includes technical details, a command list, multiple SHA256 indicators, and domains associated with the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
