Fakemoney is an Android mobile malware family associated with fraudulent investment, payout, and financial-service scam applications. It is commonly presented as an easy-earnings or payment-related app and is designed to trick users into submitting personal data under the guise of receiving money, payouts, or financial benefits. Security telemetry placed Fakemoney among the most prevalent mobile Trojan families in 2024 and 2025, and it remained highly visible in mobile threat rankings into 2026.
The family is characterized primarily by phishing-style social engineering and data harvesting rather than by classic banking-Trojan functionality. Reported Fakemoney apps impersonate financial opportunities or services and collect victim information after persuading users that they can obtain earnings or payments. This behavior aligns with credential and personal-data theft on Android devices.
Fakemoney has been observed at scale in mobile threat statistics and has repeatedly ranked among the most frequently detected Android malware verdicts. It has been described as one of the most active scam-app families in 2024, with activity still significant in subsequent quarterly reporting even when declining from earlier peaks. It often appears in the same broader Android threat landscape as Triada-infected messaging mods, Mamont banking Trojans, and other financially motivated mobile malware, but the available information supports treating Fakemoney specifically as a phishing-oriented Android infostealing Trojan family focused on harvesting user-supplied data through fake financial lures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android trojan family appearing in Q2 2026 top mobile malware detections with multiple variants.
Android trojan family appearing in the quarter's top mobile malware rankings in multiple variants.
Android trojan family with multiple variants appearing among the most frequently detected mobile malware in the quarter.
Android trojan family listed among the top mobile malware detections for the quarter.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.