Retefe (Android)

Malware type
credential-stealer, trojan
Family
Malware family
Profile updated
2026-07-07 14:09:32

Targeted industries: financial-services

Targeted regions: country_code:ch country_code:at country_code:se

Context

The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor. Further is a bank logo added to the specific Android app to trick users into thinking this is a legitimate app. Moreover, if the victim is not a real victim, the link to download the APK is not the malicious APK, but the real 'Signal Private Messenger' tool, hence the victim's phone doesn't get infected.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Retefe (report)
  • maldr0id.blogspot.ch — Android Malware Based On Sms Encryption (report)
  • blog.dornea.nu — Disect Android Apks Like A Pro Static Code Analysis (report)
  • blog.angelalonso.es — Reversing C2C Http Emmental (report)
  • blog.angelalonso.es — Reversing Sms C Protocol Of Emmental (report)
  • blog.angelalonso.es — Hunting Retefe With Splunk Some24 (report)
  • govcert.admin.ch — The Retefe Saga (report)

External references