TF-MAL-apk.antidot
📛 Threat Title
Malware family: Antidot
Description
ThreatFox malware family `apk.antidot`. Printable name: Antidot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.antidot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.antidot
IOC database
- Type
- domain
- Value
apk.antidot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.antidot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.antidot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:clickcontrol.com
Cybersecurity researchers have discovered the AntiDot botnet, a sophisticated Android malware operation that has compromised over 3,775 devices across 273 campaigns. Operated by threat group LARVA-398…
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:cybersecuritynews.com
A sophisticated new Android botnet malware called AntiDot has emerged as a significant threat to mobile device security, offering cybercriminals unprecedented control over infected devices. This malicious software operates as part of a Malware -as-a-Service (MaaS) model, marketed by threat actor LARVA-398 on underground forums as a comprehensive "3-in-1" tool that combines its own loader ...
-
web:cyble.com
Discover the 'Antidot' Android Banking Trojan: a fake Google Play update that steals credentials using overlay attacks and remote control techniques.
-
web:gbhackers.com
A new Android botnet malware named AntiDot has emerged as a formidable threat, granting cybercriminals unprecedented control over infected devices. Operated and sold by LARVA-398 as a Malware -as-a-Service (MaaS) on underground forums like XSS, AntiDot is marketed as a "3-in-1" tool, bundling a loader, packer, and botnet infrastructure into ...
-
web:malpedia.caad.fkie.fraunhofer.de
The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese, Romanian, and English, indicating potential targets in these regions. Antidot uses overlay attacks and keylogging techniques to efficiently collect sensitive information such as login credentials.
-
web:thehackernews.com
Android malware AntiDot and GodFather target mobile users with phishing, NFC attacks, and app virtualization.
-
web:www.androidpolice.com
Who is being impacted by the malware ? When the Antidot trojan attempts to access your Android, you will see a fake Google Play update, which prompts you for access to your settings upon being ...
-
web:www.pcrisk.com
AntiDot malware overview AntiDot is highly obfuscated and employs several anti-detection techniques. Like most Android-specific malicious programs, it heavily abuses the Android Accessibility Services. These services are intended to offer additional aid with device interaction to users who require it.
-
web:www.spartechsoftware.com
Cybersecurity researchers have recently exposed the inner workings of a sophisticated Android malware called AntiDot , which has compromised over 3,775 devices across 273 distinct campaigns. AntiDot is operated by the financially motivated threat actor group LARVA-398 and is actively sold as Malware -as-a-Service (MaaS) on underground forums, enabling a wide range of mobile attack campaigns.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.