Operation BlackEcho: Voice Phishing Using Fake Financial and Vaccine Apps

Black Hat Asia 2025 · Day 1 · Briefings

Overview

Operation BlackEcho details a sophisticated and evolving voice phishing campaign that leverages an intricate network of fake financial and vaccine applications to defraud victims. Presented by Keniha and Jang, security researchers from the Financial Security Institute (FSI) in South Korea, this talk provides an in-depth analysis of the attackers' methods, from initial victim recruitment and malicious app distribution to advanced voice phishing tactics and the underlying server infrastructure. The research highlights a critical and persistent threat, particularly in regions like South Korea, where mobile financial transactions are prevalent and the recommendation for antivirus software creates a fertile ground for exploitation.

Watch on YouTube

Visual summary for Operation BlackEcho: Voice Phishing Using Fake Financial and Vaccine Apps
Visual summary for Operation BlackEcho: Voice Phishing Using Fake Financial and Vaccine Apps

Key moments

  1. 0:00 Introduction to Operation Black Echo
  2. 2:27 Discovery of new multi-app malicious strategy
  3. 3:28 Origin and meaning of 'Operation Black Echo'
  4. 4:00 Detailed attack flow of Operation Black Echo
  5. 6:00 Evolution and separation of malicious apps
  6. 6:44 First app's role: financial lure and permission abuse
  7. 10:00 Second app: voice phishing, remote control, data theft
  8. 12:00 Three types of voice phishing methods

Operation BlackEcho: Voice Phishing Using Fake Financial and Vaccine Apps

Speakers: Keniha, Security Researcher, Financial Security Institute (FSI); Jang, Security Researcher, Financial Security Institute (FSI)

Conference: Black Hat Asia

YouTube: https://www.youtube.com/watch?v=VV0Ht_5YDUg

Overview

Operation BlackEcho details a sophisticated and evolving voice phishing campaign that leverages an intricate network of fake financial and vaccine applications to defraud victims. Presented by Keniha and Jang, security researchers from the Financial Security Institute (FSI) in South Korea, this talk provides an in-depth analysis of the attackers' methods, from initial victim recruitment and malicious app distribution to advanced voice phishing tactics and the underlying server infrastructure. The research highlights a critical and persistent threat, particularly in regions like South Korea, where mobile financial transactions are prevalent and the recommendation for antivirus software creates a fertile ground for exploitation.

The presentation meticulously dissects the evolution of the malicious applications, their modular architecture, and the command-and-control (C2) mechanisms employed by the threat actors. It also uncovers the psychological manipulation techniques used to pressure and isolate victims, ultimately leading to significant financial losses. The speakers emphasize the adaptability of the criminal organization, noting their shift in tactics in response to robust defensive measures. This talk is crucial for understanding the current landscape of mobile-centric financial fraud and for developing more resilient cybersecurity strategies against such multifaceted attacks.

The significance of Operation BlackEcho extends beyond South Korea, serving as a case study for how organized cybercrime adapts to technological advancements and defensive efforts. The financial damage caused by voice phishing remains alarmingly high, reaching nearly 40 million Korean Won (approximately $27,000 USD) per case in 2024, despite a decrease in the overall number of incidents since 2019. This persistent threat underscores the necessity for continuous research, public awareness, and collaborative defensive strategies across industries and government agencies.

Background

▶ Watch: Introduction to Operation Black Echo (0:00)

Voice phishing has long been a pervasive form of cybercrime, characterized by scammers tricking individuals over the phone to extract money or sensitive personal information. In South Korea, this threat has maintained a high level of severity, with substantial financial damage despite a reported decrease in the number of cases since 2019. The primary themes exploited by these campaigns often revolve around loan fraud and the impersonation of government agencies, capitalizing on victims' financial anxieties or their trust in official entities.

A critical enabler for these voice phishing attacks, particularly against smartphone users, is the deployment of malicious applications. The Financial Security Institute (FSI) in South Korea, recognizing this escalating threat, dedicates significant resources to hunting, analyzing, and responding to such malware. Their research recently uncovered a novel and concerning evolution in malicious app design: a modular approach where an initial fake financial application installs a secondary, seemingly legitimate "vaccine" or antivirus app. This tactic is particularly effective in South Korea, where the use of antivirus applications is often recommended or even required for mobile financial transactions, making victims susceptible to installing what they perceive as necessary security software.

The problem's persistence is deeply rooted in the digital habits of the Korean populace. South Korea boasts a remarkably high smartphone utilization rate, with a vast array of financial activities, from banking to loan applications, routinely conducted via mobile devices. This convenience, while beneficial, simultaneously creates a broad attack surface for cybercriminals. The criminal organization behind Operation BlackEcho skillfully exploits this environment, distributing fake financial apps that, upon installation, unleash a cascade of further attacks, including remote control, data theft, and sophisticated voice phishing operations, ultimately leading to financial fraud and identity theft.

Key Findings

▶ Watch: Origin and meaning of 'Operation Black Echo' (3:28)

Operation BlackEcho revealed a highly organized and adaptive cybercriminal enterprise employing a multi-stage attack methodology centered around evolving malicious Android applications and a robust server infrastructure. The key findings underscore the sophistication and persistence of this threat:

  • Modular Malicious App Evolution: The malicious apps, first observed in late 2021, demonstrated significant evolution. Initially, a single app would perform all malicious functions. By 2022, they separated into two distinct applications: a "first app" with a financial or government theme responsible for initial compromise and personal information theft, and a "second app" with a fake vaccine theme designed for launching attacks, including voice phishing. From July 2023, the second app further bifurcated into a second call app specifically for voice phishing calls and text messages, and a second main app for broader command execution like remote control, streaming, and data theft.
  • Sophisticated Infrastructure: The criminal organization does not rely on a single C2 server but operates a distributed infrastructure comprising six specialized servers: a landing page, a distribution server, a phishing page server, a discovery server, a C2 server, and a streaming server. Each server performs a specific role, from tricking victims into downloading apps to coordinating attacks and exfiltrating data.
  • Advanced Voice Phishing Techniques: The malicious apps enable sophisticated voice phishing by setting themselves as the default call app. They employ three main types of voice phishing: intercepting outgoing calls (e.g., to financial institutions), spoofing incoming calls (making criminal calls appear as legitimate police or bank numbers), and blocking incoming calls (blacklisting legitimate contacts or reporting hotlines like the Financial Supervisory Service). The apps also contain 93 compressed ARS files (Audio Response System) and map over 300 phone numbers to these files, creating realistic automated responses. Over 70% of these numbers belong to the second financial sector.
  • Evasion and Anti-Analysis Measures: The attackers actively employ techniques to hinder analysis and detection. Malicious apps are frequently updated during office hours (weekdays, 8-9 AM), suggesting a professional operation. They utilize commercial packers such as Dex Protector (applied to over 50% of apps) and Epsylon (used in about 10% of apps in early 2024) to conceal and obfuscate their main code. The server infrastructure incorporates multiple discovery servers and dynamically updates C2 and streaming server addresses, eliminating the need to redistribute modified apps. Furthermore, the organization abuses Cloudflare's CDN, proxy, and tunneling features to conceal services and evade detection.
  • Psychological Manipulation: Criminals use various psychological tactics, including pressing victims by impersonating authoritative figures (prosecutors, police), imposing time pressure for hasty decisions, and isolating victims by instructing them not to contact anyone else.
  • Shifting Trends ("Balloon Effect"): Due to concerted countermeasures against voice phishing in South Korea, the criminal organizations have demonstrated a "balloon effect," shifting their focus to less regulated and lower-investment crime models such as smishing (SMS phishing) and secondhand platform fraud. Traces of preparation for smishing were observed within the BlackEcho operation.

Technical Deep Dive

▶ Watch: Evolution and separation of malicious apps (6:00)

Operation BlackEcho's technical sophistication is evident in its multi-layered approach, encompassing an evolving malware ecosystem, a distributed command-and-control infrastructure, and advanced voice phishing mechanisms. The malicious apps are designed for stealth, persistence, and comprehensive control over the victim's device.

The campaign's malware initially manifested as single malicious apps in late 2021. However, by 2022, a significant architectural shift occurred: the functionality was split between a "first app" and a "second app." The first app, often disguised as a legitimate financial company or government agency application, served as the initial point of compromise. Its primary roles included installing the second app and stealing personal identifiable information (PII). This app abused Android's Accessibility Service to automatically grant itself and subsequent apps necessary permissions without explicit user consent, a common tactic for escalating privileges on Android devices.

The display methods of the first app evolved to enhance its legitimacy. Initially, it used local HTML files embedded within the app, displaying screens that mimicked financial or government interfaces. Directory names within the app, such as "CCI" (Cyber Crime Investigation) or "CU" (Credit Union), were used to represent keywords of impersonated entities. Later versions incorporated standard Android layout techniques and, eventually, redirected victims to external phishing pages to gather information. The installation method for the second app also changed: from a "drop" method, where the second app was bundled within the first, to a "download" method, where the first app acted as a downloader, fetching the second app from an external server. This "downloader" approach allowed attackers to update the second app without modifying and redistributing the first app, improving agility. The first app was adept at stealing sensitive PII, including name, phone number, social security number, and even copies of ID cards, under the guise of loan applications.

The second app, initially themed as a vaccine or antivirus application, was the core attack component. It set itself as the default call app to facilitate voice phishing and continuously ran in the background to process attacker commands, again leveraging the Accessibility Service for stealthy operation. This app was capable of handling over 50 distinct commands. From July 2023, the second app underwent further specialization, splitting into two distinct components: the second call app and the second main app. The second call app focused exclusively on voice phishing-related commands, such as managing calls and text messages. In contrast, the second main app was responsible for other functionalities, including streaming (camera, microphone, screen), remote control, and data theft.

Command execution within these second-stage apps relied on custom intents. An intent is an Android object used for inter-component communication. The attack flow involved the attacker sending commands and parameters via the C2 server. A sukus service within the app would receive these, construct a custom intent with the appropriate parameters, and dispatch it to another service (e.g., an SMS service). This target service would then execute the command (e.g., sending a text message) and report the result back to the C2 server.

The voice phishing capabilities were particularly sophisticated. The malicious apps prepared three critical elements: custom screens, ARS files, and phone numbers. They incorporated custom screens for dialers, contact lists, and call functions, allowing them to fully impersonate a legitimate phone application. A significant arsenal of 93 ARS files, compressed and stored in the app's assets directory, were meticulously mapped to over 300 phone numbers saved in a local database. When a victim initiated an outgoing call to a mapped number, the app would intercept it and play the corresponding ARS file, creating the illusion of connecting to a legitimate service. Analysis showed that over 70% of these mapped numbers belonged to the second financial sector, including saving banks, insurance companies, and credit card companies, followed by lending companies, banks, and government agencies.

Beyond ARS manipulation, the apps were designed for advanced call interception and blocking. They utilized an app ID and an app name (keyword of the impersonated entity) to coordinate attacks. The criminal organization operated with subgroups, referred to as Chongpan (exclusive distributor) and Meang (shop), which were mapped to specific app IDs. This allowed attackers from a particular subgroup (e.g., Meang 35) to target victims infected with apps bearing that specific app ID. The apps would send their app ID to the C2 server to request phone numbers for intercepting or blocking calls. For instance, if a victim called a Visa card number, the malicious app would intercept the call and redirect it to an attacker impersonating a Visa employee. Crucially, the app also blocked calls from critical entities like the Financial Supervisory Service, preventing victims from reporting the fraud.

Three common features were observed across the malicious apps:

  1. Update Statistics: The apps were frequently updated on weekdays between 8:00 AM and 9:00 AM, suggesting a professionally operated criminal organization adhering to standard office hours.
  2. Packers: To hinder analysis, the apps were protected by commercial packers. Dex Protector was applied to over 50% of the apps throughout the observation period, while Epsylon was used in approximately 10% during the first five months of 2024. These packers obfuscate and conceal the main code, making reverse engineering challenging.
  3. Keywords: Specific keywords like Huhoo (referring to the second app, which previously impersonated a fishing detection app called "hoohoo") and Packu (used in package names, certificates, and custom intents) were consistently found.

The infrastructure supporting Operation BlackEcho was meticulously designed for resilience and evasion. It comprised six distinct servers, each with a specialized role:

  • Landing Page: This server displayed a fake Google Play interface, tricking victims into believing they were downloading an official app.
  • Distribution Server: This server hosted the malicious apps. Its methods evolved from using Cintu Sava to public file-sharing services like Catbox and GoFile, then to the hosting service Tat Home, and finally, after July 2024, the organization established its own distribution server.
  • Phishing Page Server: Hosted pages designed to mimic official financial or government websites (e.g., a fake Visa card inquiry page). These pages collected PII from unsuspecting victims.

The addresses for these three servers were often visible to victims and found in plain text within the apps or communications. They frequently incorporated keywords related to impersonated entities (e.g., IBK for Industrial Bank of Korea) and epoch time values, which could be used to estimate app distribution timelines.

The remaining three servers were concealed from victims:

  • Discovery Server: This server provided dynamically updated addresses for the C2 and streaming servers. Its address was embedded in the malicious apps, but the values for C2, streaming, and alternative discovery servers were encoded using a combination of Base64 and XOR algorithms, which were also embedded within the apps.
  • C2 Server: This was the central command-and-control hub, interacting directly with the malicious apps. It issued commands, provided specific phone numbers for voice phishing, and received command results and stolen data from infected smartphones.
  • Streaming Server: This server enabled the attackers to remotely stream the victim's smartphone camera, microphone, and screen, providing real-time surveillance.

The criminal organization implemented significant measures to prevent detection and blocking. They utilized multiple discovery servers and dynamically updated the C2 and streaming server addresses. This dynamic updating meant that even if a server address was blocked, the malicious apps didn't need to be modified and redistributed, greatly enhancing their persistence. Furthermore, the organization extensively abused Cloudflare's content delivery network (CDN), proxy, and tunneling features to conceal their services, evade network-level detection, and sustain their malicious activities.

Demo / Proof of Concept

▶ Watch: First app's role: financial lure and permission abuse (6:44)

While the presentation did not include a live, real-time demonstration or proof-of-concept by the speakers, it provided compelling visual evidence and detailed descriptions of the attacker's capabilities and operational interfaces. The speakers effectively demonstrated the mechanics of the malicious apps and the control server through a series of screenshots and flowcharts derived from their analysis.

A key visualization was the main screen of the control server, which provided a simulated view of the attacker's operational dashboard. This screen was logically divided into two primary sections: an upper part that monitored the victim's call history in real-time, and a lower part that presented the infected device control menu. The most illustrative feature was the system of colored arrows in the call log:

  • Red arrow: Indicated an incoming call controlled by the criminal. This signifies a spoofed call appearing as a legitimate entity (e.g., police or financial company).
  • Green arrow: Represented a normal call log, indicating calls not directly manipulated by the attacker.
  • Blue arrow: Denoted an outgoing call controlled by the criminal, signifying an intercepted call redirected to the attacker or an ARS system.
  • Black arrow: Indicated a blocked call, demonstrating the app's ability to prevent victims from contacting legitimate entities or reporting the fraud.

This visual representation effectively conveyed how criminals gain comprehensive control over a victim's communication channels, allowing them to intercept, spoof, and block calls at will. The detailed explanation of ARS file usage, phone number mapping, and the dynamic redirection of calls further illustrated the practical execution of these sophisticated voice phishing techniques. Through these analytical visualizations and detailed technical explanations, the talk effectively demonstrated the profound impact and operational methods of Operation BlackEcho from the attacker's perspective.

Defensive Implications

▶ Watch: Three types of voice phishing methods (12:00)

Combating sophisticated voice phishing operations like Operation BlackEcho requires a multi-faceted and collaborative defense strategy involving public awareness, enhanced security research, and coordinated efforts from law enforcement, financial institutions, and telecommunication providers.

For individual users and the general public, the primary defense lies in heightened awareness and cautious digital behavior. It is critical to avoid downloading unknown applications from unofficial sources, as these are the initial vectors for infection. Users must also exercise extreme caution when accessing unfamiliar URLs, particularly those received via SMS or social media, as these often lead to fake landing pages or phishing sites. Education about the psychological tactics employed by criminals—such as impersonating authority figures, creating a sense of urgency, and instructing victims to isolate themselves—is vital for recognizing and resisting social engineering attempts. Furthermore, verifying the legitimacy of financial or government communications through official, independently sourced channels (not numbers provided by the caller) is paramount.

Financial institutions and security companies must enhance their threat intelligence and information sharing mechanisms. The Financial Security Institute (FSI) exemplifies this with their "fishing curse chain" response system:

  1. Detection: Proactively monitoring IP addresses used by voice phishing criminals and leveraging intelligence services like URLScan.io and Criminal IP to detect fishing sites.
  2. Information Gathering: Extracting basic information about detected phishing sites, malicious apps, control information, and fake phone numbers.
  3. Information Sharing: Sharing identified phishing sites and associated intelligence with financial companies and other security entities.
  4. Reporting and Blocking: Reporting the findings to KISA (Korea Internet & Security Agency), a public organization in charge of information security in Korea. KISA then reviews the reports and works with Korean ISPs to block victim access to these malicious sites.

Security researchers must continuously enhance their skills to keep pace with the increasingly sophisticated evolution of malicious applications. The modular design, dynamic C2 updates, and use of commercial packers like Dex Protector and Epsylon by BlackEcho highlight the need for advanced malware analysis capabilities and anti-obfuscation techniques. Identifying potential threats early and understanding their technical underpinnings is crucial for developing effective countermeasures.

At an industry and government level, sustained collaboration is essential. In South Korea, efforts like the Voice Missing Crime TF (Task Force) involving police and financial companies have demonstrated success in making voice phishing a "high-risk, low-return business." This integrated approach, combining law enforcement actions with financial sector safeguards, is key. However, the "balloon effect," where criminals shift to less regulated areas like smishing and secondhand platform fraud, underscores the need for constant vigilance and adaptability in defensive strategies. Regulations and enforcement must expand to cover emerging fraud vectors.

Ultimately, cybersecurity is a shared responsibility. By fostering public awareness, strengthening inter-agency information sharing, investing in advanced security research, and adapting regulatory frameworks, society can collectively build more robust defenses against evolving cybercrime operations like Operation BlackEcho.

Key Takeaways

  • Sophisticated and Evolving Threat: Operation BlackEcho represents a highly organized and adaptive voice phishing campaign that utilizes multi-stage malicious apps and a distributed server infrastructure to target victims, primarily in South Korea.
  • Modular Malware Architecture: The malicious apps demonstrate significant evolution, splitting into specialized components (fake financial app, fake vaccine app, second call app, second main app) to enhance functionality, evade detection, and maintain persistence.
  • Advanced Voice Phishing Techniques: Attackers employ intricate methods, including intercepting outgoing calls, spoofing incoming calls, blocking legitimate contacts, and using pre-recorded ARS files, to create a convincing illusion of legitimacy and control victim communications.
  • Robust Evasion and Anti-Analysis Measures: The criminal organization utilizes commercial packers (Dex Protector, Epsylon), dynamic C2 server address updates, and abuse of Cloudflare services to obfuscate their operations, hinder analysis, and ensure infrastructure resilience.
  • Psychological Manipulation: Beyond technical exploits, the attackers leverage potent psychological tactics such as impersonation of authority, time pressure, and victim isolation to coerce individuals into making financially detrimental decisions.
  • Adaptability of Cybercriminals: Successful defensive measures against voice phishing have led to a "balloon effect," prompting criminals to shift their focus to emerging and less regulated fraud models like smishing and secondhand platform fraud, necessitating continuous adaptation in cybersecurity strategies.

About the Speaker(s)

Keniha is a security researcher at the Financial Security Institute (FSI) in South Korea. Her primary responsibilities include the analysis and response to Android malware, contributing significantly to the understanding and mitigation of mobile-centric threats. In the Operation BlackEcho presentation, Keniha covered the background of the operation, the malicious apps, and the infrastructure utilized by the attackers.

Jang is also a security researcher at the Financial Security Institute (FSI) in South Korea. His expertise lies in the detection and response to phishing sites. During the presentation, Jang detailed the voice phishing methodologies, countermeasure strategies, and the evolving trends in cybercrime, providing crucial insights into the broader impact and defense against such operations.

The research for Operation BlackEcho also had significant contributions from their co-workers, Kuku Kim, Chinyong, and Panguang, who collaborated on researching the malicious apps and the underlying infrastructure.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Operation BlackEcho delivers a critical, deep dive into a sophisticated and evolving voice phishing campaign. Keniha and Jang from FSI meticulously dissect the adversary's multi-stage Android malware, revealing a modular architecture, advanced call interception techniques, and a resilient, distributed C2 infrastructure. This isn't just another threat report; it's a forensic examination of how a highly organized criminal enterprise adapts, evades, and exploits the mobile financial ecosystem, providing invaluable, actionable intelligence for defenders struggling against persistent, high-impact financial fraud.

Heather Calloway (CISO) — STRONG ACCEPT

Operation BlackEcho presents a clear, detailed analysis of an evolving voice phishing campaign with significant real-world financial impact. The research meticulously dissects the sophisticated, modular malware architecture and adaptive infrastructure, providing a crucial understanding of how organized cybercrime operates and evades defenses. While specifically focused on South Korea, the insights into criminal adaptability and the need for coordinated, multi-stakeholder response are universally relevant for security leaders and policymakers.

→ Top-rated talks at Black Hat Asia 2025

All talks from Black Hat Asia 2025