Skip to content

Malware

Retefe

The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor.

Retefe is a Android malware family.

Background

The Android component tied to Retefe functions as an SMS stealer whose job is to relay mTAN codes back to the attacker. To make the app look trustworthy, a bank logo is embedded into it so users believe it is genuine. The operators also gate distribution: when a target is not considered a legitimate victim, the download link serves the real 'Signal Private Messenger' app rather than the malicious APK, so that person's phone is left uninfected.


Source: Malpedia (Fraunhofer FKIE).