A new variant of the malicious software FakeBank Android includes the capability to monitor phone calls to bank numbers and divert them to malicious users.

FakeBank is a banking trojan that operates by displaying fake login screens over a legitimate banking application. It can get onto a whitelist and stay active when a mobile phone's screen is locked and uses TeamViewer to give attackers full access.
In the new version the malicious software continues to operate like a regular banking trojan but with a unique addition, call control. Every time the user attempts to call their bank's number, FakeBank monitors the call and changes the number to a predefined one, leading users to scammers who collect their banking information. It can also work the opposite way; the operators of FakeBank can call victims from a special number, which is also included in the malware's configuration file, appearing on the user's phone as if it comes from their bank. This allows scammers to carry out fraud without the victim suspecting any breach.
According to Symantec, this new variant of FakeBank is active only in South Korea. Experts found the new FakeBank in over 20 Android applications that are distributed via third-party stores and through links on social networking sites. This once again shows the huge problem with third-party stores and the applications distributed from there. Users must pay special attention to the applications they install, what permissions they grant to them, and whether those permissions are justified based on the characteristics of the application.
We should emphasize how last week Google published the annual security report for the Android operating system, stating that now over 50 billion apps are checked daily and the chances of someone getting infected from the Google Play Store are infinitesimally small.
