PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

'FakeCall' Android Malware Can Now Hijack Bank Calls

The malware can infiltrate Android devices through malicious apps installed using APKs.

 & Jibin Joseph Contributor

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS
(Credit: i_am_zews/Shutterstock.com)

Cybercriminals are now using an updated version of Android malware, dubbed "FakeCall," to take over phone dialers and intercept calls made to banks, according to a report from mobile security platform Zimperium.

Kaspersky first reported the malware in 2022. It mimicked banking apps and let users make calls through them. The attackers overlaid the bank's actual number on victims' screens and impersonated bank employees to make the calls more believable to extract sensitive information.

The updated version of the malware takes the scheme a step further. "The attack typically begins when victims download an APK file onto an Android mobile device through a phishing attack," malware researcher Fernando Ortega explains. Users will be unaware of the takeover until they uninstall the malicious app, he adds.

During installation, it asks the user to set itself as the default calling app. Once permitted, the malware gains significant control via Android's accessibility service and oversees all incoming and outgoing calls. If a user tries to call the bank, it reroutes the call to the attacker's number.

According to the new research, the malware has received a few other upgrades as well. It can now monitor the vulnerable device's Bluetooth status and screen activity and see the data on the screen. It can also potentially grant device permissions to apps without user consent and give attackers remote device control. 

The best way to avoid this malware is to stop installing apps using APKs obtained from untrustworthy sources—and go for vetted, verified Android apps instead. You can also look into Android antivirus apps for an extra layer of security.

About Our Expert

Jibin Joseph

Jibin Joseph

Contributor

Jibin is a tech news writer based out of Ahmedabad, India. Previously, he served as the editor of iGeeksBlog and is a self-proclaimed tech enthusiast who loves breaking down complex information for a broader audience.

Read full bio