Faketoken – Android Banking Malware Top-up Infected Mobile Devices to send Offensive SMS Messages

A banking trojan dubbed Faketoken found infected more than 5,000 smartphones and started sending out offensive text messages.

The malware found to active since 2014, the malicious app aimed to hack victim’s account and withdraw money, they also capable of intercepting text messages received on victim mobiles.

Faketoken Campaign

Starting from 2016, the malware evolved as a full-fledged mobile banking Trojan, it overlay’s on other apps to trick the users entering into logins, passwords, and bank card info.

In another campaign in 2017, it mimics a lot of apps such as mobile banking apps, e-wallets such as Google Pay, and even taxi service apps to steal bank account data and card details.

Security researchers from Kaspersky observed the return of the Android banking malware, infected more than 5,000 smartphones and sends offensive text messages.

The banking trojan asks to set the victim as a default text message app so that it can intercept any SMS messages such as OTP sent to the infected device.

“But for banking malware to turn into a mass texting tool? We had never seen that before”, Kaspersky said.

Before starting to send premium messages that charge the infected device owner’s account, Faketoken checks that the victim has sufficient funds, if the victim has enough funds then malware uses to top up the mobile account for sending messages.

“Many of the smartphones infected by Faketoken were texting a foreign number, so the messages the Trojan sent cost the users quite a bit.”

The good news is that Faketoken not distributed through the play store, it appears using third-party stores. It is always recommended to download apps only from the official store.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago