s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-apk.antidot

📛 Threat Title

Malware family: Antidot

Category: Antidot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.antidot`. Printable name: Antidot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.antidot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.antidot

IOC database

Type
domain
Value
apk.antidot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.antidot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.antidot

References (1)

Remediations (10)

  • web:clickcontrol.com

    Cybersecurity researchers have discovered the AntiDot botnet, a sophisticated Android malware operation that has compromised over 3,775 devices across 273 campaigns. Operated by threat group LARVA-398…

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:cybersecuritynews.com

    A sophisticated new Android botnet malware called AntiDot has emerged as a significant threat to mobile device security, offering cybercriminals unprecedented control over infected devices. This malicious software operates as part of a Malware -as-a-Service (MaaS) model, marketed by threat actor LARVA-398 on underground forums as a comprehensive "3-in-1" tool that combines its own loader ...

  • web:cyble.com

    Discover the 'Antidot' Android Banking Trojan: a fake Google Play update that steals credentials using overlay attacks and remote control techniques.

  • web:gbhackers.com

    A new Android botnet malware named AntiDot has emerged as a formidable threat, granting cybercriminals unprecedented control over infected devices. Operated and sold by LARVA-398 as a Malware -as-a-Service (MaaS) on underground forums like XSS, AntiDot is marketed as a "3-in-1" tool, bundling a loader, packer, and botnet infrastructure into ...

  • web:malpedia.caad.fkie.fraunhofer.de

    The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese, Romanian, and English, indicating potential targets in these regions. Antidot uses overlay attacks and keylogging techniques to efficiently collect sensitive information such as login credentials.

  • web:thehackernews.com

    Android malware AntiDot and GodFather target mobile users with phishing, NFC attacks, and app virtualization.

  • web:www.androidpolice.com

    Who is being impacted by the malware ? When the Antidot trojan attempts to access your Android, you will see a fake Google Play update, which prompts you for access to your settings upon being ...

  • web:www.pcrisk.com

    AntiDot malware overview AntiDot is highly obfuscated and employs several anti-detection techniques. Like most Android-specific malicious programs, it heavily abuses the Android Accessibility Services. These services are intended to offer additional aid with device interaction to users who require it.

  • web:www.spartechsoftware.com

    Cybersecurity researchers have recently exposed the inner workings of a sophisticated Android malware called AntiDot , which has compromised over 3,775 devices across 273 distinct campaigns. AntiDot is operated by the financially motivated threat actor group LARVA-398 and is actively sold as Malware -as-a-Service (MaaS) on underground forums, enabling a wide range of mobile attack campaigns.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.