HomeSecurityAndroid malware "FakeCalls" targets financial companies in South Korea

Android malware “FakeCalls” targets financial companies in South Korea

A new Android vishing (voice phishing) malware tool called “FakeCalls” has been detected and is targeting victims in South Korea by impersonating 20 top financial institutions in the region.

See also: Rubrik: Under hacking attack due to GoAnywhere zero-day

FakeCalls

The Check Point Research (CPR) team has named the malware “FakeCalls” and it tricks victims with fake loan offers that ask for confirmation of their credit card numbers in order to steal them.

"The FakeCalls malware possesses the functionality of a Swiss army knife, capable of not only achieving its primary goal but also extracting personal data from the victim," said CPR cybersecurity researcher Alexander Chailytko.

On Tuesday, CPR published a report detailing the detection of over 2,500 instances of FakeCalls malware disguised as financial institutions and deployed with evasion tactics.

See also: Adobe ColdFusion zero-day: Update immediately

Furthermore, the team revealed that the malware creators have done everything they can to avoid detection by antivirus programs. To achieve this goal, they used several unique evasion techniques that had not been previously observed in previous CPR tests.

“The malware developers took great care in the technical aspects of their creation as well as implementing many unique and effective anti-analysis techniques,” Chailytko explained. “In addition, they devised mechanisms for covert analysis of the command-and-control servers behind the enterprises.”

The security expert warned that the same strategies used by FakeCalls could potentially be replicated to target other global markets.

"I recommend that Android users in South Korea not provide personal information over the phone and be suspicious when receiving phone calls from unknown numbers," Chailytko concluded.

"FakeCalls" Android malware targets financial companies in South Korea

To help protect against vishing attacks similar to the one described in this report, we have included several security recommendations.

See also: LockBit ransomware says it hacked Essendant

Be on the lookout for any calls claiming to be from your bank or credit card companies and asking for personal information, such as account numbers or passwords. Also, be aware that these types of calls may come from unknown numbers – scammers often use spoofing software to make it appear as if they are calling from a legitimate number when they are not. If you receive such a call, do not give out any personal information and hang up immediately. Additionally, make sure all accounts are secure with strong passwords and two-factor authentication enabled whenever possible, and watch out for suspicious links sent via text or voicemail, which may contain malware designed specifically to steal data from mobile devices.

The CPR report confirms Proofpoint's statement last December that vishing will become a more significant attack vector in 2023.

Information source: infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS