{"id":167384,"date":"2023-04-20T18:27:34","date_gmt":"2023-04-21T01:27:34","guid":{"rendered":"https:\/\/www.mcafee.com\/blogs\/?p=167384"},"modified":"2024-06-11T09:43:08","modified_gmt":"2024-06-11T16:43:08","slug":"fakecalls-android-malware-abusing-legitimate-signing-key","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/","title":{"rendered":"Fakecalls Android Malware Abuses Legitimate Signing Key"},"content":{"rendered":"<p><span class=\"TextRun SCXW1925763 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW1925763 BCX0\">Authored by Dexter Shin<\/span><\/span><span class=\"EOP SCXW1925763 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW230285841 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW230285841 BCX0\">McAfee Mobile Research Team <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">found<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">an Android<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">banking trojan <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">signed with a <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">key<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">used by legitimate <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">apps in South Korea<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> last year<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">.<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">By <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">design<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">,<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> Android requires that all applications<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">must<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> be signed with a <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">key<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">, <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW230285841 BCX0\">in other words<\/span>\u00a0<span class=\"NormalTextRun SCXW230285841 BCX0\">a keystore,<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">so they can <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">be installed or update<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">d<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">. <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">Because this<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">key <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">can only be used by the developer <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">who <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">created it<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">, an application signed with the same <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">key<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">is<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> assumed <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">to <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">belong to the same developer. <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">That is the case of this Android <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">b<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">anking trojan <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">that uses this legitimate <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">signing key<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> to <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">bypass signature-based detection techniques<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">.<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">And these banking trojans weren&#8217;t distributed on Google Play or official app stores until now.<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">This threat <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW230285841 BCX0\">had been<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">disclosed<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> to <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">the <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">company<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">that owns<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> the legitimate <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">key <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">last year <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">and <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">t<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">he company has taken <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">precautions<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">. T<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">he company has<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> confirmed <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">that <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">they have replace<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">d<\/span> <span class=\"NormalTextRun SCXW230285841 BCX0\">the <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">signing key<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> and <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">currently, <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">all the<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">ir<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> legitimate apps<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\"> are signed with a new <\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">signing key<\/span><span class=\"NormalTextRun SCXW230285841 BCX0\">.<\/span><\/span><span class=\"EOP SCXW230285841 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun MacChromeBold SCXW182654745 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW182654745 BCX0\">Android malware using a legitimate <\/span><span class=\"NormalTextRun SCXW182654745 BCX0\">signing <\/span><span class=\"NormalTextRun SCXW182654745 BCX0\">key<\/span><\/span><span class=\"EOP SCXW182654745 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/h2>\n<p><span class=\"TextRun SCXW71465546 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW71465546 BCX0\">While <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">tracking<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">the Android <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">banking trojan<\/span> <span class=\"NormalTextRun SpellingErrorV2Themed SCXW71465546 BCX0\">Fakecalls<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> we found a <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">sample<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> using the same <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">signing key<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">as <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">a<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">well<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">&#8211;<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">known <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">app<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> in Korea<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">.<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">This app <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">is developed by <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">a <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">reputable<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">IT<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> services<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">company<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">with <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">extensive<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> business<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">es<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> across various sectors,<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> including but not limited to IT,<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> gam<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">ing<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">, <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">payment,<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> and advertis<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">ing<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">.<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">We confirmed that most of the <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">malicious samples<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> using this <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">key<\/span> <span class=\"NormalTextRun SCXW71465546 BCX0\">pretend to be a <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">bank<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">ing<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> app<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\"> as they use the <\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">same icon as the real banking apps<\/span><span class=\"NormalTextRun SCXW71465546 BCX0\">.<\/span><\/span><span class=\"EOP SCXW71465546 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167385\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.04.png\" alt=\"\" width=\"957\" height=\"488\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.04.png 957w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.04-300x153.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.04-768x392.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.04-205x105.png 205w\" sizes=\"auto, (max-width: 957px) 100vw, 957px\" \/><\/p>\n<p style=\"text-align: center;\"><span class=\"TextRun MacChromeBold SCXW71569076 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW71569076 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><\/span><span class=\"FieldRange SCXW71569076 BCX0\"><span class=\"TextRun MacChromeBold SCXW71569076 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW71569076 BCX0\" data-ccp-parastyle=\"caption\">1<\/span><\/span><\/span><span class=\"TextRun MacChromeBold SCXW71569076 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW71569076 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SCXW71569076 BCX0\" data-ccp-parastyle=\"caption\">M<\/span><span class=\"NormalTextRun SCXW71569076 BCX0\" data-ccp-parastyle=\"caption\">alware<\/span><span class=\"NormalTextRun SCXW71569076 BCX0\" data-ccp-parastyle=\"caption\"> and <\/span><span class=\"NormalTextRun SCXW71569076 BCX0\" data-ccp-parastyle=\"caption\">legitimate app on Google Play<\/span><\/span><span class=\"EOP SCXW71569076 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun MacChromeBold SCXW257440723 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW257440723 BCX0\">Distribution method and latest s<\/span><span class=\"NormalTextRun SCXW257440723 BCX0\">t<\/span><span class=\"NormalTextRun SCXW257440723 BCX0\">atus<\/span><\/span><span class=\"EOP SCXW257440723 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/h2>\n<p><span class=\"TextRun SCXW84855252 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW84855252 BCX0\">Domains verified <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">last <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">August when we first discovered the samples are now down.<\/span> <span class=\"NormalTextRun SCXW84855252 BCX0\">However<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">,<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\"> we investigated URLs related <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">to <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">this <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">malware<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\"> and <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">we <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">found<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\"> similar <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">ones<\/span> <span class=\"NormalTextRun SCXW84855252 BCX0\">related to this threat<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">.<\/span> <span class=\"NormalTextRun SCXW84855252 BCX0\">Among them, we <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">identified<\/span> <span class=\"NormalTextRun SCXW84855252 BCX0\">a <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">phishing site that <\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">is<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\"> still alive during our research.<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\"> The site is also disguised as a banking site<\/span><span class=\"NormalTextRun SCXW84855252 BCX0\">.<\/span><\/span><span class=\"EOP SCXW84855252 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167399\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.51.png\" alt=\"\" width=\"704\" height=\"1032\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.51.png 704w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.51-205x300.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.51-699x1024.png 699w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.50.51-88x129.png 88w\" sizes=\"auto, (max-width: 704px) 100vw, 704px\" \/><\/p>\n<p style=\"text-align: center;\"><span class=\"TextRun MacChromeBold SCXW238913791 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">2<\/span><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">A phishing page disguised as <\/span><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">a <\/span><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">Korean <\/span><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">banking <\/span><span class=\"NormalTextRun SCXW238913791 BCX0\" data-ccp-parastyle=\"caption\">site<\/span><\/span><span class=\"EOP SCXW238913791 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW202006993 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW202006993 BCX0\">We also found that<\/span><span class=\"NormalTextRun SCXW202006993 BCX0\"> they updated <\/span><span class=\"NormalTextRun SCXW202006993 BCX0\">the <\/span><span class=\"NormalTextRun SCXW202006993 BCX0\">domain information<\/span><span class=\"NormalTextRun SCXW202006993 BCX0\"> of this web page <\/span><span class=\"NormalTextRun SCXW202006993 BCX0\">a few days before our investigation<\/span><span class=\"NormalTextRun SCXW202006993 BCX0\">.<\/span><\/span><span class=\"EOP SCXW202006993 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167413\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.17.png\" alt=\"\" width=\"991\" height=\"276\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.17.png 991w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.17-300x84.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.17-768x214.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.17-205x57.png 205w\" sizes=\"auto, (max-width: 991px) 100vw, 991px\" \/><\/p>\n<p><span class=\"TextRun SCXW42433795 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42433795 BCX0\">So<\/span> <span class=\"NormalTextRun SCXW42433795 BCX0\">we <\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">took a deeper look into this <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW42433795 BCX0\">domain<\/span> <span class=\"NormalTextRun SCXW42433795 BCX0\">and we found <\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">additional<\/span> <span class=\"NormalTextRun SCXW42433795 BCX0\">unusual IP<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\"> addresses that led us to the <\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">C<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">ommand and <\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">c<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">ontrol<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">(<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">C<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">2)<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\"> server<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\"> admin pages<\/span> <span class=\"NormalTextRun SCXW42433795 BCX0\">used by the cybercriminals <\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">to control <\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">the <\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">infected devices<\/span><span class=\"NormalTextRun SCXW42433795 BCX0\">.<\/span><\/span><span class=\"EOP SCXW42433795 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167427\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.44.png\" alt=\"\" width=\"979\" height=\"649\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.44.png 979w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.44-300x199.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.44-768x509.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.51.44-195x129.png 195w\" sizes=\"auto, (max-width: 979px) 100vw, 979px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167441\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.06.png\" alt=\"\" width=\"992\" height=\"663\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.06.png 992w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.06-300x201.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.06-768x513.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.06-193x129.png 193w\" sizes=\"auto, (max-width: 992px) 100vw, 992px\" \/><\/p>\n<p style=\"text-align: center;\"><span class=\"TextRun MacChromeBold SCXW6771470 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><\/span><span class=\"FieldRange SCXW6771470 BCX0\"><span class=\"TextRun MacChromeBold SCXW6771470 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">3<\/span><\/span><\/span><span class=\"TextRun MacChromeBold SCXW6771470 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">Fakecalls<\/span> <span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">C<\/span><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">ommand and <\/span><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">control(C2) <\/span><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">admin <\/span><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">page<\/span><span class=\"NormalTextRun SCXW6771470 BCX0\" data-ccp-parastyle=\"caption\">s<\/span><\/span><span class=\"EOP SCXW6771470 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun MacChromeBold SCXW35672106 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW35672106 BCX0\">How does it <\/span><span class=\"NormalTextRun SCXW35672106 BCX0\">work<\/span><\/span><span class=\"EOP SCXW35672106 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/h2>\n<p><span class=\"TextRun SCXW192434006 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW192434006 BCX0\">When <\/span><span class=\"NormalTextRun SCXW192434006 BCX0\">we check the<\/span> <span class=\"NormalTextRun SCXW192434006 BCX0\">APK file structure, <\/span><span class=\"NormalTextRun SCXW192434006 BCX0\">we can see that<\/span><span class=\"NormalTextRun SCXW192434006 BCX0\"> this malware uses <\/span><span class=\"NormalTextRun SCXW192434006 BCX0\">a <\/span><span class=\"NormalTextRun SCXW192434006 BCX0\">packer to avoid analysis and detection.<\/span> <span class=\"NormalTextRun SCXW192434006 BCX0\">The malicious code is encrypted in one of the files below<\/span><span class=\"NormalTextRun SCXW192434006 BCX0\">.<\/span><\/span><span class=\"EOP SCXW192434006 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167455\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.22.png\" alt=\"\" width=\"985\" height=\"270\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.22.png 985w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.22-300x82.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.22-768x211.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.22-205x56.png 205w\" sizes=\"auto, (max-width: 985px) 100vw, 985px\" \/><\/p>\n<p style=\"text-align: center;\"><span class=\"TextRun MacChromeBold SCXW155383776 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW155383776 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><span class=\"NormalTextRun SCXW155383776 BCX0\" data-ccp-parastyle=\"caption\">4<\/span><span class=\"NormalTextRun SCXW155383776 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SCXW155383776 BCX0\" data-ccp-parastyle=\"caption\">Tencent\u2019s <\/span><span class=\"NormalTextRun SCXW155383776 BCX0\" data-ccp-parastyle=\"caption\">Legu<\/span><span class=\"NormalTextRun SCXW155383776 BCX0\" data-ccp-parastyle=\"caption\"> Packer<\/span> <span class=\"NormalTextRun SCXW155383776 BCX0\" data-ccp-parastyle=\"caption\">libraries<\/span><\/span><span class=\"EOP SCXW155383776 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">After decrypting the DEX file, we found some unusual functionality. The code below gets the Android package information from a file with a HTML extension.<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p style=\"text-align: center;\"><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167469\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.48.png\" alt=\"\" width=\"1037\" height=\"259\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.48.png 1037w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.48-300x75.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.48-1024x256.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.48-768x192.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.52.48-205x51.png 205w\" sizes=\"auto, (max-width: 1037px) 100vw, 1037px\" \/><span class=\"TextRun MacChromeBold SCXW199474089 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW199474089 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><span class=\"NormalTextRun SCXW199474089 BCX0\" data-ccp-parastyle=\"caption\">5<\/span><span class=\"NormalTextRun SCXW199474089 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SCXW199474089 BCX0\" data-ccp-parastyle=\"caption\">Questionable code in the decrypted DEX file<\/span><\/span><span class=\"EOP SCXW199474089 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This file is in fact another APK (Android Application) rather than a traditional HTML file designed to be displayed in a web browser.<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167483\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.11.png\" alt=\"\" width=\"990\" height=\"265\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.11.png 990w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.11-300x80.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.11-768x206.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.11-205x55.png 205w\" sizes=\"auto, (max-width: 990px) 100vw, 990px\" \/><span class=\"TextRun MacChromeBold SCXW202691518 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW202691518 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><span class=\"NormalTextRun SCXW202691518 BCX0\" data-ccp-parastyle=\"caption\">6<\/span><span class=\"NormalTextRun SCXW202691518 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SCXW202691518 BCX0\" data-ccp-parastyle=\"caption\">APK file disguised as an HTML <\/span><span class=\"NormalTextRun SCXW202691518 BCX0\" data-ccp-parastyle=\"caption\">file<\/span><\/span><span class=\"EOP SCXW202691518 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW255630471 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW255630471 BCX0\">When <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">the user<\/span> <span class=\"NormalTextRun SCXW255630471 BCX0\">launches<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> the malware<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">,<\/span> <span class=\"NormalTextRun SCXW255630471 BCX0\">it <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">immediately<\/span> <span class=\"NormalTextRun SCXW255630471 BCX0\">asks for<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> permission to install <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">another<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> app.<\/span> <span class=\"NormalTextRun SCXW255630471 BCX0\">Then <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">it<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> tr<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">ies to install<\/span> <span class=\"NormalTextRun SCXW255630471 BCX0\">an application <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">stored in <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">the <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">\u201c<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">assets<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">\u201d<\/span> <span class=\"NormalTextRun SCXW255630471 BCX0\">directory<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> as <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">\u201c<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">introduction.html<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">\u201d.<\/span> <span class=\"NormalTextRun SCXW255630471 BCX0\">The<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> \u201c<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">introduction.html<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">\u201d is<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">\u00a0<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">an<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> APK file<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> and <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">real <\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">malicious<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> behavior<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\"> happen<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">s here<\/span><span class=\"NormalTextRun SCXW255630471 BCX0\">.<\/span><\/span><span class=\"EOP SCXW255630471 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167498\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.25.png\" alt=\"\" width=\"947\" height=\"574\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.25.png 947w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.25-300x182.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.25-768x466.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.25-205x124.png 205w\" sizes=\"auto, (max-width: 947px) 100vw, 947px\" \/><\/p>\n<p style=\"text-align: center;\"><span class=\"TextRun MacChromeBold SCXW241908023 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW241908023 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><span class=\"NormalTextRun SCXW241908023 BCX0\" data-ccp-parastyle=\"caption\">7<\/span><span class=\"NormalTextRun SCXW241908023 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SCXW241908023 BCX0\" data-ccp-parastyle=\"caption\">Dropper\u00a0<\/span><span class=\"NormalTextRun SCXW241908023 BCX0\" data-ccp-parastyle=\"caption\">asks\u00a0you to install<\/span> <span class=\"NormalTextRun SCXW241908023 BCX0\" data-ccp-parastyle=\"caption\">the main <\/span><span class=\"NormalTextRun SCXW241908023 BCX0\" data-ccp-parastyle=\"caption\">payload<\/span><\/span><span class=\"EOP SCXW241908023 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW157190703 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW157190703 BCX0\">When the dropped payload is about to be installed, it asks for several permissions <\/span><span class=\"NormalTextRun SCXW157190703 BCX0\">to access sensitive personal information<\/span><span class=\"NormalTextRun SCXW157190703 BCX0\">.<\/span><\/span><span class=\"EOP SCXW157190703 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167512\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.50.png\" alt=\"\" width=\"362\" height=\"636\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.50.png 362w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.50-171x300.png 171w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.53.50-73x129.png 73w\" sizes=\"auto, (max-width: 362px) 100vw, 362px\" \/><\/p>\n<p style=\"text-align: center;\"><span class=\"TextRun MacChromeBold SCXW64108529 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW64108529 BCX0\" data-ccp-parastyle=\"caption\">Figure <\/span><span class=\"NormalTextRun SCXW64108529 BCX0\" data-ccp-parastyle=\"caption\">8<\/span><span class=\"NormalTextRun SCXW64108529 BCX0\" data-ccp-parastyle=\"caption\">. <\/span><span class=\"NormalTextRun SCXW64108529 BCX0\" data-ccp-parastyle=\"caption\">Permissions required by the main malicious <\/span><span class=\"NormalTextRun SCXW64108529 BCX0\" data-ccp-parastyle=\"caption\">application<\/span><\/span><span class=\"EOP SCXW64108529 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW167159081 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW167159081 BCX0\">It also<\/span><span class=\"NormalTextRun SCXW167159081 BCX0\"> registers <\/span><span class=\"NormalTextRun SCXW167159081 BCX0\">several<\/span><span class=\"NormalTextRun SCXW167159081 BCX0\"> services and receivers to control notifications from the device and to receive commands from <\/span><span class=\"NormalTextRun SCXW167159081 BCX0\">a remote Command and Control server<\/span><span class=\"NormalTextRun SCXW167159081 BCX0\">.<\/span><\/span><span class=\"EOP SCXW167159081 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-167526\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.54.13.png\" alt=\"\" width=\"583\" height=\"556\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.54.13.png 583w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.54.13-300x286.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.54.13-135x129.png 135w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/CleanShot-2023-04-20-at-16.54.13-24x24.png 24w\" sizes=\"auto, (max-width: 583px) 100vw, 583px\" \/><\/p>\n<p style=\"text-align: center;\"><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span>Figure 9. Services and receivers registered by the main payload<\/p>\n<p><span class=\"TextRun SCXW194903090 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW194903090 BCX0\">By contrast,<\/span> <span class=\"NormalTextRun SCXW194903090 BCX0\">the malware<\/span> <span class=\"NormalTextRun SCXW194903090 BCX0\">uses<\/span> <span class=\"NormalTextRun SCXW194903090 BCX0\">a legitimate <\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">p<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">ush<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\"> SDK<\/span> <span class=\"NormalTextRun SCXW194903090 BCX0\">to<\/span> <span class=\"NormalTextRun SCXW194903090 BCX0\">receive <\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">command<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">s<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\"> from <\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">a remote server<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">.<\/span> <span class=\"NormalTextRun SCXW194903090 BCX0\">Here are <\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">the<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\"> complete list of commands and <\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">their<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\"> purpose<\/span><span class=\"NormalTextRun SCXW194903090 BCX0\">.<\/span><\/span><span class=\"EOP SCXW194903090 BCX0\" data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<table data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1184\" aria-rowcount=\"29\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"65536\"><strong>Command name<\/strong><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/td>\n<td data-celllook=\"65536\"><strong>Purpose\u00a0<\/strong><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">note<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[1519],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">sms message upload<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">incoming_transfer<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">caller number upload<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">del_phone_record<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">delete call log<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">zhuanyi<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">set call forwarding with parameter<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">clear_note<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">delete sms message<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">assign_zhuanyi<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">set call forwarding<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">file<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">file upload<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">lanjie<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">block sms message from specified numbers<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">allfiles<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">find all possible files and upload them<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">email_send<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">send email<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">record_telephone<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">call recording on<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"13\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">inout<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">re-mapping on C2 server<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"14\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">blacklist<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">register as blacklist<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"15\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">listener_num<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">no function<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"16\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">no_listener_num<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">disable monitoring a specific number<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"17\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">rebuild<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">reset and reconnect with C2<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"18\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">deleteFile<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">delete file<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"19\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">num_address_list<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">contacts upload<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"20\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">addContact<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">add contacts<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"21\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">all_address_list<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">call record upload<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"22\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">deleteContact<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">delete contacts<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"23\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">note_intercept<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">intercept sms message from specified numbers<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"24\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">intercept_all_phone<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">intercept sms message from all<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"25\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">clear_date<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">delete all file<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"26\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">clear_phone_contact<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">delete all contacts<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"27\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">clear_phone_record<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">delete all call log<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"28\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">per_note<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">quick sms message upload<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"29\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">soft_name<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">app name upload<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Cybercriminals are constantly evolving and using new ways to bypass security checks, such as abusing legitimate signing keys. Fortunately, there was no damage to users due to this signing key leak. However, we recommend that users <a href=\"https:\/\/www.mcafee.com\/en-us\/antivirus\/mobile.html?path=blogs\">install security software on their devices<\/a> to respond to these threats. Also, users are recommended to download and use apps from the official app stores.<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\"><a href=\"https:\/\/www.mcafee.com\/en-us\/antivirus\/mobile.html?path=blogs\">McAfee Mobile Security<\/a> detects this threat as Android\/Banker regardless of the application, is signed with the previously legitimate signing key.\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Indicators of Compromise<\/span><\/b><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<table data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1184\" aria-rowcount=\"14\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"65536\"><span data-contrast=\"auto\">SHA256<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/td>\n<td data-celllook=\"65536\"><span data-contrast=\"auto\">Name<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/td>\n<td data-celllook=\"65536\"><span data-contrast=\"auto\">Type<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">7f4670ae852ec26f890129a4a3d3e95c079f2f289e16f1aa089c86ea7077b3d8<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;469777462&quot;:[1519],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\uc2e0\ud55c\uc2e0\uccad\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Dropper<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">9e7c9b04afe839d1b7d7959ad0092524fd4c6b67d1b6e5c2cb07bb67b8465eda<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\uc2e0\ud55c\uc2e0\uccad\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Dropper<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">21ec124012faad074ee1881236c6cde7691e3932276af9d59259df707c68f9dc<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\uc2e0\ud55c\uc2e0\uccad\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Dropper<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">9621d951c8115e1cc4cf7bd1838b8e659c7dea5d338a80e29ca52a8a58812579<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\uc2e0\ud55c\uc2e0\uccad\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Dropper<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">60f5deb79791d2e8c2799e9af52adca5df66d1304310d1f185cec9163deb37a2<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">756cffef2dc660a241ed0f52c07134b7ea7419402a89d700dffee4cc6e9d5bb6<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">6634fdaa22db46a6f231c827106485b8572d066498fc0c39bf8e9beb22c028f6<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">52021a13e2cd7bead4f338c8342cc933010478a18dfa4275bf999d2bc777dc6b<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">125772aac026d7783b50a2a7e17e65b9256db5c8585324d34b2e066b13fc9e12<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">a320c0815e09138541e9a03c030f30214c4ebaa9106b25d3a20177b5c0ef38b3<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">c7f32890d6d8c3402601743655f4ac2f7390351046f6d454387c874f5c6fe31f<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"13\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">dbc7a29f6e1e91780916be66c5bdaa609371b026d2a8f9a640563b4a47ceaf92<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"14\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">e6c74ef62c0e267d1990d8b4d0a620a7d090bfb38545cc966b5ef5fc8731bc24<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">\ubcf4\uc548\uc778\uc99d\uc11c<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:110,&quot;335559991&quot;:110,&quot;335559992&quot;:50}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Banker<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Domains:<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<ul>\n<li data-leveltext=\"\uf06c\" data-font=\"Wingdings\" data-listid=\"1\" data-list-defn-props=\"{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:760,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Wingdings&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf06c&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"0\" data-aria-level=\"1\"><span data-contrast=\"auto\">http[:\/\/]o20-app.dark-app.net<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559795&quot;:0}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf06c\" data-font=\"Wingdings\" data-listid=\"1\" data-list-defn-props=\"{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:760,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Wingdings&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf06c&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"0\" data-aria-level=\"1\"><span data-contrast=\"auto\">http[:\/\/]o20.orange-app.today<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559795&quot;:0}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"\uf06c\" data-font=\"Wingdings\" data-listid=\"1\" data-list-defn-props=\"{&quot;335551671&quot;:0,&quot;335552541&quot;:1,&quot;335559684&quot;:-2,&quot;335559685&quot;:760,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Wingdings&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;\uf06c&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}\" aria-setsize=\"-1\" data-aria-posinset=\"0\" data-aria-level=\"1\"><span data-contrast=\"auto\">http[:\/\/]orange20.orange-app.today<\/span><span data-ccp-props=\"{&quot;134245417&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559795&quot;:0}\">\u00a0<\/span><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Authored by Dexter Shin\u00a0 McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate&#8230;<\/p>\n","protected":false},"author":695,"featured_media":167546,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1838,442],"tags":[180],"coauthors":[4136],"class_list":["post-167384","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mobile-security","category-mcafee-labs","tag-malware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Fakecalls Android Malware Abuses Legitimate Signing Key | McAfee Blog<\/title>\n<meta name=\"description\" content=\"Authored by Dexter Shin\u00a0 McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate apps in South Korea last year.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fakecalls Android Malware Abuses Legitimate Signing Key | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"Authored by Dexter Shin\u00a0 McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate apps in South Korea last year.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2023-04-21T01:27:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-11T16:43:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"McAfee Labs\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee_Labs\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee Labs\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/\"},\"author\":{\"name\":\"McAfee Labs\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad\"},\"headline\":\"Fakecalls Android Malware Abuses Legitimate Signing Key\",\"datePublished\":\"2023-04-21T01:27:34+00:00\",\"dateModified\":\"2024-06-11T16:43:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/\"},\"wordCount\":1131,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png\",\"keywords\":[\"malware\"],\"articleSection\":[\"Mobile Security\",\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/\",\"name\":\"Fakecalls Android Malware Abuses Legitimate Signing Key | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png\",\"datePublished\":\"2023-04-21T01:27:34+00:00\",\"dateModified\":\"2024-06-11T16:43:08+00:00\",\"description\":\"Authored by Dexter Shin\u00a0 McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate apps in South Korea last year.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png\",\"width\":300,\"height\":200},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Fakecalls Android Malware Abuses Legitimate Signing Key\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad\",\"name\":\"McAfee Labs\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/af947d76ffbef8521094b476cf8050c3\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg\",\"caption\":\"McAfee Labs\"},\"description\":\"McAfee Labs is one of the leading sources for threat research, threat intelligence, and cybersecurity thought leadership. See our blog posts below for more information.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee_Labs\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee-labs\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fakecalls Android Malware Abuses Legitimate Signing Key | McAfee Blog","description":"Authored by Dexter Shin\u00a0 McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate apps in South Korea last year.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Fakecalls Android Malware Abuses Legitimate Signing Key | McAfee Blog","og_description":"Authored by Dexter Shin\u00a0 McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate apps in South Korea last year.","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2023-04-21T01:27:34+00:00","article_modified_time":"2024-06-11T16:43:08+00:00","og_image":[{"width":300,"height":200,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png","type":"image\/png"}],"author":"McAfee Labs","twitter_card":"summary_large_image","twitter_creator":"@McAfee_Labs","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee Labs","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/"},"author":{"name":"McAfee Labs","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad"},"headline":"Fakecalls Android Malware Abuses Legitimate Signing Key","datePublished":"2023-04-21T01:27:34+00:00","dateModified":"2024-06-11T16:43:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/"},"wordCount":1131,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png","keywords":["malware"],"articleSection":["Mobile Security","McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/","name":"Fakecalls Android Malware Abuses Legitimate Signing Key | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png","datePublished":"2023-04-21T01:27:34+00:00","dateModified":"2024-06-11T16:43:08+00:00","description":"Authored by Dexter Shin\u00a0 McAfee Mobile Research Team found an Android banking trojan signed with a key used by legitimate apps in South Korea last year.","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#primaryimage","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/04\/300x200_Blog_Fakecalls.png","width":300,"height":200},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/fakecalls-android-malware-abusing-legitimate-signing-key\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"Fakecalls Android Malware Abuses Legitimate Signing Key"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad","name":"McAfee Labs","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/af947d76ffbef8521094b476cf8050c3","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg","caption":"McAfee Labs"},"description":"McAfee Labs is one of the leading sources for threat research, threat intelligence, and cybersecurity thought leadership. See our blog posts below for more information.","sameAs":["https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee_Labs"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee-labs\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/167384","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/695"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=167384"}],"version-history":[{"count":9,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/167384\/revisions"}],"predecessor-version":[{"id":193681,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/167384\/revisions\/193681"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media\/167546"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=167384"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=167384"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=167384"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=167384"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}