TF-MAL-apk.copybara
📛 Threat Title
Malware family: Copybara
Description
ThreatFox malware family `apk.copybara`. Printable name: Copybara.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.copybara
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.copybara
IOC database
- Type
- domain
- Value
apk.copybara- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.copybara
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.copybara
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Copybara .
-
web:cybernoz.com
A new variant of Copybara , an Android malware family , has been detected to be active since November 2023 spreading through vishing attacks and leveraging the MQTT protocol for C2 communication. The malware exploits the Accessibility Service to gain control over infected devices and downloads phishing pages impersonating cryptocurrency exchanges and financial institutions, which trick victims
-
web:cybersecuritynews.com
A new variant of Copybara , an Android malware family , has been detected to be active since November 2023 spreading through vishing attacks and leveraging the MQTT protocol for C2 communication. The malware exploits the Accessibility Service to gain control over infected devices and downloads phishing pages impersonating cryptocurrency exchanges and financial institutions, which trick victims ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Copybara malware family including references, samples and yara signatures.
-
web:securitricks.com
Description This report presents a comprehensive technical analysis of a newly discovered variant of the Copybara Android malware . The malware , which emerged in November 2021, is primarily spread through voice phishing attacks. It utilizes the MQTT protocol for command-and-control communication and abuses Android's Accessibility Service to exert control over infected devices. The malware ...
-
web:securityboulevard.com
IntroductionZscaler ThreatLabz recently analyzed a new variant of Copybara , which is an Android malware family that emerged in November 2021. The malware is primarily spread through voice phishing (vishing) attacks, where victims receive instructions over the phone to install the Android malware . This new variant of Copybara has been active since November 2023, and utilizes the MQTT protocol ...
-
web:socprime.com
The article details a cryptomining campaign involving the redtail malware family , which is delivered through HTTP requests that exploit CVE-2024-4577 in PHP. Threat actors send Base64-encoded payloads that retrieve and run a self-replicating script named cve_2024_4577.selfrep.
-
web:www.heise.de
A new variant of the banking Trojan Copybara is currently spreading via phishing attacks on Android smartphones and tablets.
-
web:www.tinextacyber.com
JokerRAT Panel On the port 51144, on the path /login we can find the login for the JokerRAT Panel, which is the panel used by this variant of Copybara . Judging from its name, it may be related to the Joker malware family , however aside from the Cleafy report and some mentions on Twitter/X both this panel and Mr.Robot can't be found anywhere else.
-
web:www.zscaler.com
Introduction Zscaler ThreatLabz recently analyzed a new variant of Copybara , which is an Android malware family that emerged in November 2021. The malware is primarily spread through voice phishing (vishing) attacks, where victims receive instructions over the phone to install the Android malware . This new variant of Copybara has been active since November 2023, and utilizes the MQTT protocol ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.