Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » A new variant of the FakeCall malware hijacks Android devices for fraudulent banking calls
Global Security

A new variant of the FakeCall malware hijacks Android devices for fraudulent banking calls

AdminBy AdminNovember 4, 2024No Comments3 Mins Read
FakeCall Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 4, 2024Ravi LakshmananMobile Security / Financial Fraud

FakeCall malware

Cybersecurity researchers have discovered a new version of a well-known Android malware family called FakeCall which uses voice phishing techniques (aka vishing) to trick users into parting with personal information.

“FakeCall is an extremely sophisticated Vishing attack that uses malware to gain almost complete control over a mobile device, including intercepting incoming and outgoing calls,” said Zimperium researcher Fernando Ortega. said in a report published last week.

“Victims are tricked into calling fake phone numbers controlled by the attacker and mimicking the normal user experience on the device.”

FakeCall, which is also tracked under the names FakeCalls and Letscall, has been the subject of numerous analyses Kaspersky, Check Pointand ThreatFabric since its appearance in April 2022. Previous waves of attacks have mostly targeted mobile users in South Korea.

Cyber ​​security

Names of malicious packages ie. dropper programs that carry malware are listed below –

  • com.qaz123789.serviceone
  • com.sbbqcfnvd.skgkkvba
  • com.securegroup.assistant
  • com.seplatmsm.skfplzbh
  • eugmx.xjrhry.eroreqxo
  • gqcvctl.msthh.swxgkyv
  • ouyudz.wqrecg.blxal
  • plnfexcq.fehlwuggm.kyxvb
  • xkeqoi.iochvm.vmyab

Like other Android banking malware families that are known to abuse Accessibility Services APIs to take control of devices and perform malicious actions, FakeCall uses them to collect information displayed on the screen and grant itself additional permissions to necessary measures.

Some of the other spying features include capturing a wide range of information such as SMS messages, contact lists, location and installed apps, taking pictures, recording live feed from the rear and front cameras, adding and removing contacts, capturing audio, downloading images and impersonating a video stream of all actions on the device using the MediaProjection API.

Newer versions are also designed to monitor Bluetooth status and device screen status. But what makes the malware more dangerous is that it instructs the user to set the app as the default dialer, which gives it the ability to monitor all incoming and outgoing calls.

This not only allows FakeCall to intercept and hijack calls, but also allows them to change a dialed number, such as a bank number, to a fraudulent number under their control and lure victims into unintended actions.

In contrast, previous versions of FakeCall were found to encourage users to call a bank from a malicious app that impersonates various financial institutions under the guise of offering a loan with a lower interest rate.

Cyber ​​security

“When a compromised individual attempts to contact their financial institution, the malware redirects the call to a fake number controlled by the attacker,” Ortega said.

“The malware will trick the user by showing a convincing fake user interface that appears to be a legitimate Android call interface, showing the phone number of a real bank. The victim will not be aware of the manipulation, as the fake interface of the malware will mimic the actual banking experience. , which allows an attacker to obtain sensitive information or gain unauthorized access to a victim’s financial accounts.”

The emergence of sophisticated new phishing strategies (aka mobile phishing) underscores the contraindication to improved security protections and the widespread use of caller ID applications that can flag suspicious numbers and alert users to potential spam.

In recent months, Google has also been experimenting with a security initiative that automatically blocks sideloading of potentially dangerous Android apps, including those that request accessibility services, in Singapore, Thailand, Brazil and India.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.