An Android banking trojan, which researchers are calling Fakecalls, hijacks victims' calls to bank customer support and connects victims directly to the cybercriminals who run the malware.
The banking trojan appears as a legitimate mobile application belonging to a popular bank and has all the details of the bank it is impersonating: official logo, customer support number, etc.
See also: “Escobar” banking trojan steals Google Authenticator MFA codes

When the victim tries to call the bank’s customer service, Fakecalls drops the connection and displays the dialing screen, which is almost indistinguishable from the real one. The victim sees the real bank number on the screen, but the connection is made to the cybercriminals. The fraudsters pose as bank customer service representatives and can obtain credentials that would give them access to the victim’s money.
The Fakecalls mobile banking trojan can do this because at the time of installation it requests several permissions that give it access to the contact list, microphone, camera, geolocation, and call management.
According to a report by Kaspersky, the malware appeared last year and mainly targets users in South Korea who are customers of popular banks such as KakaoBank or Kookmin Bank (KB).
See also: Banking malware: The most dangerous trojans that have ever existed!
Fakecalls banking trojan: Direct connection to criminals
Kaspersky analyzed the malware and saw how it works. Researchers also noticed that the malware can play a pre-recorded message that mimics those commonly used by banks to welcome customers seeking support.
Here are two examples of the pre-recorded message (in Korean):
“Hello. Thank you for calling KakaoBank. Our call center is currently experiencing an unusually high volume of calls. An advisor will speak to you as soon as possible. <…> To improve the quality of service, your conversation will be recorded”.
“Welcome to Kookmin Bank. Your conversation will be recorded. We will now connect you with an advisor”.

Fakecalls banking trojan: Complete espionage of the victim
The truth is that users can tell that something is wrong if they are careful when downloading the malicious Fakecalls app. The permissions it requests during installation are numerous and essentially allow criminals to spy on the victim by transmitting real-time audio and video from the device, view its location, copy files (contacts, files such as photos and videos) and text message history.
“ These permissions allow the malware not only to spy on the user but to control their device to some extent, giving the Trojan the ability to reject incoming calls and delete them from the history. This allows fraudsters, among other things, to block and hide real calls from banks ,” Kaspersky said in its report.
Currently, the Fakecalls malware has been observed to only support the Korean language. However, attackers could easily add more languages to expand to other regions.
Kaspersky suggests some protection tips, including downloading apps only from official stores and paying attention to potentially dangerous permissions an app requests (access to calls, messages, accessibility), especially if it doesn't need them. In addition, the researchers advise users not to share confidential information over the phone (credentials , PIN, card security code, confirmation codes) and to use protection software antivirus and malware
Source: www.bleepingcomputer.com
