logo

Fake Fortnite Apps Scamming & Spying on Android Gamers

ID: c8a56cd2-5a4d-5f20-9ce6-8d785a4f2ed4

STIX ID: report--c8a56cd2-5a4d-5f20-9ce6-8d785a4f2ed4

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ observed multiple fake Fortnite Android apps delivering distinct malicious behaviors: a spyware RAT (capable of harvesting calls/SMS/contacts, keylogging, camera/audio capture, wiping, and abusing Accessibility), a CoinHive-based cryptominer embedded in the APK assets that significantly increases CPU/battery usage, and scam apps (V‑Bucks generators and revenue-driving survey installers) distributed via malicious domains and a Play Store listing—one fake app had thousands of installs before removal. The report provides example URLs/domains, behavioral details, screenshots, and user remediation steps (remove app, revoke Accessibility, disable unknown sources).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.