Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Technology

FakeCall Hijacks Bank Calls—Android's New Check Only Covers Incoming Calls

|Updated: |Author: QUASA Editorial Team|5 min read| 1481
FakeCall Hijacks Bank Calls—Android's New Check Only Covers Incoming Calls

FakeCall remains a serious Android banking threat because an infected phone can redirect an outgoing call to a bank while showing the legitimate number on a counterfeit call screen. The stealth findings behind this warning date to October 2024, and no newer primary analysis establishing a fresh FakeCall campaign was identified.

Android’s 2026 security roadmap includes new checks for calls that appear to come from financial institutions. The crucial limitation is unchanged: those checks concern incoming calls, while FakeCall manipulates an outgoing call after malicious software has gained control of the device’s calling interface.

FakeCall compromises the phone before the victim calls a bank

The attack starts with installation rather than an ordinary fraudulent phone call. A phishing lure persuades the user to download an Android package, which acts as a dropper for a second-stage payload that communicates with an attacker-controlled command-and-control server.

FakeCall then tries to become the default call handler. That role allows it to manage incoming and outgoing calls, monitor numbers being dialed and replace the normal Android dialer with its own interface.

Zimperium’s October 2024 analysis of 13 apps and two DEX files documents dynamically decrypted code, functionality moved into native code and a mechanism that substitutes an attacker-controlled destination while displaying the bank’s real number. The visible number therefore cannot establish where the call was connected once the dialer itself has been compromised.

The examined capabilities extended beyond call redirection. They included remote taps through accessibility services, screen capture, audio recording and access to contacts, messages, call logs, location and stored images. Some newly observed components appeared unfinished, so the analysis did not establish that every capability was operational in every sample.

This makes FakeCall different from conventional caller-ID spoofing. Spoofing falsifies the identity presented for an incoming call; FakeCall operates from inside the phone and can control the experience after the user initiates a call.

Android’s bank-call verification addresses a different attack

Google’s May 2026 Android security post outlines verified financial calls for Android 11 and later, initially involving Revolut, Itaú and Nubank, as well as planned Android 17 monitoring for hidden icons, background launches and accessibility abuse. For a verified financial call, Android asks the installed, signed-in app of a participating institution whether an apparent incoming call is genuine and can end the call if the app indicates that the institution is not calling.

That design is useful against a scammer who calls a customer while impersonating a participating bank. It does not authenticate an outgoing number, inspect where a malicious default dialer routes the call or remove malware already controlling the phone.

Coverage also depends on the financial institution participating, its app being installed and the customer being signed in. The initial rollout was limited rather than universal, so the absence of a warning does not prove that an apparent bank call is genuine.

The planned Android 17 controls are more closely aligned with some of FakeCall’s methods because they watch for suspicious application behavior and restrict accessibility-service access under Advanced Protection. They may reduce opportunities for covert control, but the roadmap does not establish that every Android device, sideloaded package or FakeCall variant is covered.

The most important warning signs appear during installation

A purported banking, security or utility app delivered through a message, unfamiliar website or unsolicited APK should not need to replace the phone’s dialer. A request to become the default calling app is particularly significant because it grants authority over the interface a user would normally rely on when contacting a bank.

Requests for accessibility access, screen capture, microphone, camera, messages, contacts or call logs deserve similar scrutiny when those functions do not match the app’s stated purpose. No single permission proves that an app is malicious, but an unfamiliar sideloaded app seeking several powerful permissions should not be trusted merely because its screens look convincing.

Google Play’s current Play Protect guidance says the service checks apps from Google Play and other sources and may warn about, disable or remove harmful software. Keeping that scanning enabled adds a useful layer, but it does not make an unusual permission request safe or validate an APK supplied by an unknown party.

What to do if a bank call may have been redirected

End the conversation without sharing credentials, payment-card details, PINs or one-time codes. Contact the bank from a different trusted device, using a number printed on the physical card or obtained from the institution’s official website or verified app; the number displayed by a possibly compromised dialer is not an independent contact channel.

Tell the bank that the Android phone may be infected and that a support call could have been redirected. The institution can determine whether accounts, cards, recent transactions or authentication credentials require protective action.

On the affected device, inspect the default phone app and recently installed applications, run Play Protect and remove unfamiliar software where possible. If an app resists removal, returns after deletion or held extensive accessibility and remote-control privileges, stop using the phone for banking and seek qualified recovery assistance.

A factory reset may ultimately be appropriate, but preserve any information requested by the bank or an incident responder before erasing the device. The central distinction remains practical: incoming-call verification can challenge some impersonation attempts, but it cannot establish the destination of an outgoing call controlled by malware already inside the phone.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

1