FakeCalls is an Android banking trojan associated with voice-phishing operations targeting South Korea. It masquerades as legitimate financial applications, including numerous bank and financial-service brands, to gain victim trust and facilitate fraudulent interactions. A defining feature is its ability to imitate conversations with bank employees during phone calls, including caller-ID deception and use of prerecorded audio, enabling social-engineering scenarios in which victims believe they are speaking with legitimate institutions.
Beyond impersonation, FakeCalls functions as a mobile data-theft implant. It can access call logs, text message history, contact lists, and files stored on the device, including media such as photos and videos, and transmit stolen data to command-and-control infrastructure. It can also manipulate call-log records, including deleting incoming-call entries, which supports defense evasion and concealment of malicious activity.
Operationally, FakeCalls has used a staged infection design in which a dropper component deploys and launches a secondary payload. Reported samples include anti-analysis measures intended to hinder APK parsing and reverse engineering, as well as concealed command-and-control resolution through dead-drop techniques using legitimate web services and other resolver locations. Some variants also support live audio and video streaming from infected devices under remote operator control.
FakeCalls has been publicly linked to infrastructure assessed as overlapping with DPRK-associated activity, and reporting has assessed the campaign as likely attributable to North Korean operators. Its tradecraft combines mobile banking-trojan behavior, surveillance, exfiltration, and voice-phishing enablement against Android users in the South Korean financial sector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
We discovered more than 2500 samples of the FakeCalls malware ... and implemented anti-analysis (also called evasions) techniques.
The first evasion is called “Multi-Disk.” ... Based on the very large values in the disk number fields, we understand that malware developers edited these fields and entries.
The malware contains an encrypted string with a link to Google Drive where the file is stored. ... The name of the file is encrypted with AES.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
Network communication The malware developers implemented several ways to keep their real Command-and-Control (C&C) servers hidden: reading the data via dead drop resolvers in Google Drive or using an arbitrary Web server.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan targeting South Korea; the article links infrastructure overlap between a DPRK-linked actor and indicators previously documented for FakeCalls.
Android malware targeting South Korean users by impersonating financial apps, conducting voice-phishing calls, stealing private and financial data, dropping a secondary APK payload, capturing live audio/video streams from the device, and using dead-drop resolvers such as Google Drive or arbitrary web servers to hide C2 infrastructure.
Android malware that accesses and exfiltrates files including photos and videos.
Android malware that accesses and exfiltrates files including photos and videos.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.