Uploaded December 2024 | Updated September 2026, 4 days ago
FakeCall, an Android banking trojan, has evolved with dangerous new capabilities. It now hijacks outgoing calls to banks, rerouting them to attackers, while convincing victims they’re speaking to their financial institution.
The malware sets itself as the default call handler, allowing it to intercept and redirect calls to attacker-controlled numbers while showing a fake UI mimicking the Android dialer. FakeCall can capture live audio, video, and even screenshots. It uses Accessibility Services to gain control over the device, granting itself permissions and performing actions like unlocking screens and accessing files.
Recent updates include features like Bluetooth listening, screen monitoring, and enhanced command-and-control capabilities for attackers to manipulate infected devices remotely.
Follow me:
Mastodon: https://infosec.exchange/@skickar
Thanks to our sponsor Varonis ⬇️
LinkedIn: / varonis
Visit our website: varonis.com/kody
FakeCall, an Android banking trojan, has evolved with dangerous new capabilities. It now hijacks outgoing calls to banks, rerouting them to attackers, while convincing victims they’re speaking to their financial institution.
The malware sets itself as the default call handler, allowing it to intercept and redirect calls to attacker-controlled numbers while showing a fake UI mimicking the Android dialer. FakeCall can capture live audio, video, and even screenshots. It uses Accessibility Services to gain control over the device, granting itself permissions and performing actions like unlocking screens and accessing files.
Recent updates include features like Bluetooth listening, screen monitoring, and enhanced command-and-control capabilities for attackers to manipulate infected devices remotely.
Follow me:
Mastodon: https://infosec.exchange/@skickar
Thanks to our sponsor Varonis ⬇️
LinkedIn: / varonis
Visit our website: varonis.com/kody










