FakeSpy is an Android information-stealing malware family used in long-running mobile fraud campaigns, particularly against users in Japan and South Korea. It commonly masquerades as trusted local postal, logistics, courier, e-commerce, telecommunications, financial, or other consumer-facing applications and is frequently delivered through SMS phishing campaigns that direct victims to malicious download pages hosting trojanized Android apps. FakeSpy has also been associated with broader mobile cybercrime activity linked to infrastructure overlap with XLoader and possible ties to operators connected to the Yanbian Gang, although shared-service use remains an alternative explanation.
On infected devices, FakeSpy collects a broad set of victim data, including SMS messages, contact lists, call records, installed application lists, device identifiers, subscriber information, phone numbers, operating system version, and device model information. It exfiltrates stolen data over HTTP and can monitor incoming SMS messages in near real time. The malware can send SMS messages from compromised devices and has been described as capable of supporting further fraud operations by interacting with messaging functionality.
FakeSpy also implements persistence on Android by registering for boot-related broadcast intents so that it can restart after device reboot. Variants have used encrypted configuration data and concealed command-and-control addressing through external online profiles and similar indirection mechanisms to complicate blocking and analysis. Some samples abuse Android JavaScriptInterface functionality to download and execute remote JavaScript that invokes internal app functions.
Beyond straightforward information theft, FakeSpy has been observed checking infected devices for banking-related applications and replacing targeted legitimate apps with counterfeit or repackaged versions that imitate the originals in order to phish credentials. It has also checked for digital currency trading and e-commerce applications, indicating victim profiling for financially motivated follow-on activity. In this role, FakeSpy can function as a delivery vector for banking-trojan-style fraud in addition to its core infostealer behavior.
The malware has been repeatedly used in campaigns themed around delivery and postal notifications, making smishing a defining distribution mechanism. It is widely tracked as a prominent Android mobile threat focused on credential and data theft, financial fraud enablement, and persistent access to victim messaging and device data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Meanwhile, we released our findings on FakeSpy in June after it infected Android users via SMS phishing or SMiShing to launch info-stealing attacks.
It is known to infect victims with the following range of malware families for the Android OS: FakeCop, FakeSpy, MoqHao and FunkyBot.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
These SMS messages are stolen and uploaded to the C&C server.
AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; BRATA can use both HTTP and WebSockets to communicate with the C2 server; LightSpy has used both HTTPS and Websockets to communicate with the C2.
We used VirusTotal to search for an XLoader sample... and learned that the sample was downloaded from a malicious domain... When we analyzed a FakeSpy sample... we discovered that it was downloaded from the same malicious domain.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware that disguises itself as local postal service apps.
Android spyware that can send SMS messages.
Android malware masquerading as postal service apps that collects installed application lists.
Mobile spyware that collects SMS messages from infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.