s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.copybara

📛 Threat Title

Malware family: Copybara

Category: Copybara First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.copybara`. Printable name: Copybara.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.copybara VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.copybara

IOC database

Type
domain
Value
apk.copybara
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.copybara

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.copybara

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Copybara .

  • web:cybernoz.com

    A new variant of Copybara , an Android malware family , has been detected to be active since November 2023 spreading through vishing attacks and leveraging the MQTT protocol for C2 communication. The malware exploits the Accessibility Service to gain control over infected devices and downloads phishing pages impersonating cryptocurrency exchanges and financial institutions, which trick victims

  • web:cybersecuritynews.com

    A new variant of Copybara , an Android malware family , has been detected to be active since November 2023 spreading through vishing attacks and leveraging the MQTT protocol for C2 communication. The malware exploits the Accessibility Service to gain control over infected devices and downloads phishing pages impersonating cryptocurrency exchanges and financial institutions, which trick victims ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Copybara malware family including references, samples and yara signatures.

  • web:securitricks.com

    Description This report presents a comprehensive technical analysis of a newly discovered variant of the Copybara Android malware . The malware , which emerged in November 2021, is primarily spread through voice phishing attacks. It utilizes the MQTT protocol for command-and-control communication and abuses Android's Accessibility Service to exert control over infected devices. The malware ...

  • web:securityboulevard.com

    IntroductionZscaler ThreatLabz recently analyzed a new variant of Copybara , which is an Android malware family that emerged in November 2021. The malware is primarily spread through voice phishing (vishing) attacks, where victims receive instructions over the phone to install the Android malware . This new variant of Copybara has been active since November 2023, and utilizes the MQTT protocol ...

  • web:socprime.com

    The article details a cryptomining campaign involving the redtail malware family , which is delivered through HTTP requests that exploit CVE-2024-4577 in PHP. Threat actors send Base64-encoded payloads that retrieve and run a self-replicating script named cve_2024_4577.selfrep.

  • web:www.heise.de

    A new variant of the banking Trojan Copybara is currently spreading via phishing attacks on Android smartphones and tablets.

  • web:www.tinextacyber.com

    JokerRAT Panel On the port 51144, on the path /login we can find the login for the JokerRAT Panel, which is the panel used by this variant of Copybara . Judging from its name, it may be related to the Joker malware family , however aside from the Cleafy report and some mentions on Twitter/X both this panel and Mr.Robot can't be found anywhere else.

  • web:www.zscaler.com

    Introduction Zscaler ThreatLabz recently analyzed a new variant of Copybara , which is an Android malware family that emerged in November 2021. The malware is primarily spread through voice phishing (vishing) attacks, where victims receive instructions over the phone to install the Android malware . This new variant of Copybara has been active since November 2023, and utilizes the MQTT protocol ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.