logo

New Variant of FakeCop Targeting Users from Japan

ID: 9a005557-989a-53f1-8c5f-93f49b9f98ae

STIX ID: report--9a005557-989a-53f1-8c5f-93f49b9f98ae

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-18

Date Updated: 2026-07-16

...
...

Cyble Research Labs discovered a FakeCop Android spyware campaign targeting users in Japan: malicious APKs impersonate legitimate security/anti-virus apps, use a native .so-based packer to decrypt an embedded DEX at runtime, and perform spyware actions (collect contacts/SMS/app lists, retrieve hardware IDs, send/delete SMS) while contacting C2 servers obtained via a proxy URL; the report provides multiple SHA256 IOCs and C2/proxy URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.