FakeSpy

Malware family · 5 sample(s) · 5 indicator record(s) · 4 signing certificate(s)

About FakeSpy

Android spyware posing as legitimate postal/ delivery-service apps, exfiltrating SMS and contact data to a PHP panel. The panel base URL is an http:// const-string in the MyService$ReThread (or MeService$ReThread) run() loop; some builds instead carry CONFIG_URL / IP_ADDRESS / LOGS_URL as static field values of Lorg/red/cute/common/Constant;.

Indicators

IndicatorTypeSampleFirst seen
182.162.104.181/ ip 51793a9bc21e… 2018-12-18
182.162.104.202/ ip a8e7f53427ff… 2019-10-07
182.162.104.202/ ip b2b43c197af5… 2018-12-12
211.169.248.242/ ip 4c41274f3927… 2018-11-19
45.120.69.10/ ip fa70929f9589… 2018-12-12