FakeSpy

MITRE ATT&CK: S0509 View on attack.mitre.org

Aliases: FakeSpy

First seen
2018-06-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-05-01 11:55:19
Profile updated
2026-07-07 12:59:39

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Targeted regions: country_code:jp country_code:kr country_code:tw country_code:cn country_code:hk

Context

FakeSpy is Android spyware that has been operated by the Chinese threat actor behind the Roaming Mantis campaigns.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to FakeSpy (S0509). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 94ff87c81a50d25e9acf7c46ec463f0aff88483eb4f63339cd833595d8b76cef 2026-05-01 1

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Broadcast Receivers (attack-pattern)
  • Software Discovery (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • System Checks (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • System Information Discovery (attack-pattern)
  • SMS Control (attack-pattern)
  • SMS Messages (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Contact List (attack-pattern)
  • Web Protocols (attack-pattern)

Reports & references

  • Trend Micro — A Look Into The Connection Between Xloader And Fakespy And Their Possible Ties With The Yanbian Gang (report)
  • Trend Micro — Fakespy Android Information Stealing Malware Targets Japanese And Korean Speaking Users (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Fakespy (report)
  • medium.com — The Roamingmantis Groups Expansion To European Apple Accounts And Android Devices E6381723C681 (report)
  • Trend Micro — A Look Into The Connection Between Xloader And Fakespy And Their Possible Ties With The Yanbian Gang (report)
  • Trend Micro — Fakespy Android Information Stealing Malware Targets Japanese And Korean Speaking Users (report)
  • MITRE ATT&CK — S0509 (report)
  • cybereason.com — Fakespy Masquerades As Postal Service Apps Around The World (report)

External references