FakeToken is an Android banking Trojan family associated with mobile financial fraud. It is tracked in antivirus nomenclature as Trojan-Banker.AndroidOS.Faketoken and has been observed among the mobile banking malware families encountered by users in Kaspersky mobile threat telemetry, including activity noted in 2026. The family targets Android devices and is categorized as banking malware rather than generic adware or riskware.
FakeToken is used to compromise mobile users in financial-theft operations. As a banking Trojan, it is intended to abuse access on infected devices to facilitate theft related to banking activity and payment workflows. Public reporting in the supplied material does not provide high-confidence detail on its exact infection chain, persistence model, or specific fraud mechanisms for the cited period, so those aspects cannot be stated here with confidence.
Within the broader Android threat landscape, FakeToken appears alongside other banking Trojan families such as Mamont, Rewardsteal, and Creduz, indicating continued circulation of multiple financially motivated Android malware lineages. The available information supports classifying FakeToken as an Android banking Trojan, but does not support more specific claims about delivery vectors, targeted sectors beyond mobile banking users, or additional capabilities for this dataset.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan family listed among the top mobile bankers in Q2 2026.
Android banking trojan family listed among the top banker threats in the quarter.
Android banking trojan family listed among the top mobile banking threats in Q2 2026.
Android banking trojan family observed among active mobile banker threats in the quarter.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.