FakeSpy
Malware family · 5 sample(s) · 5 indicator record(s) · 4 signing certificate(s)
About FakeSpy
Android spyware posing as legitimate postal/ delivery-service apps, exfiltrating SMS and contact data to a PHP panel. The panel base URL is an http:// const-string in the MyService$ReThread (or MeService$ReThread) run() loop; some builds instead carry CONFIG_URL / IP_ADDRESS / LOGS_URL as static field values of Lorg/red/cute/common/Constant;.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 182.162.104.181/ | ip | 51793a9bc21e… | 2018-12-18 |
| 182.162.104.202/ | ip | a8e7f53427ff… | 2019-10-07 |
| 182.162.104.202/ | ip | b2b43c197af5… | 2018-12-12 |
| 211.169.248.242/ | ip | 4c41274f3927… | 2018-11-19 |
| 45.120.69.10/ | ip | fa70929f9589… | 2018-12-12 |