Retefe (Android)
- Malware type
- credential-stealer, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 14:09:32
Targeted industries: financial-services
Targeted regions: country_code:ch country_code:at country_code:se
Context
The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor. Further is a bank logo added to the specific Android app to trick users into thinking this is a legitimate app. Moreover, if the victim is not a real victim, the link to download the APK is not the malicious APK, but the real 'Signal Private Messenger' tool, hence the victim's phone doesn't get infected.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Retefe (report)
- maldr0id.blogspot.ch — Android Malware Based On Sms Encryption (report)
- blog.dornea.nu — Disect Android Apks Like A Pro Static Code Analysis (report)
- blog.angelalonso.es — Reversing C2C Http Emmental (report)
- blog.angelalonso.es — Reversing Sms C Protocol Of Emmental (report)
- blog.angelalonso.es — Hunting Retefe With Splunk Some24 (report)
- govcert.admin.ch — The Retefe Saga (report)