s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.salvador

📛 Threat Title

Malware family: Salvador Stealer

Category: Salvador Stealer First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.salvador`. Printable name: Salvador Stealer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.salvador VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.salvador

IOC database

Type
domain
Value
apk.salvador
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.salvador

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.salvador

References (1)

Remediations (10)

  • web:any.run

    Salvador malware distributes as Stealer -as-a-service and targets both individuals and organizations exfiltrating banking credentials.

  • web:anyrun.substack.com

    In this report, we examine an Android malware sample recently collected and analyzed by our team. This malware masquerades as a banking application and is built to steal sensitive user information. During the analysis, we came across internal references to " Salvador ," so we decided to name it Salvador Stealer . Real-time visibility into mobile malware behavior is crucial for security teams ...

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as SalvadorStealer .

  • web:blog.gridinsoft.com

    Salvador Stealer is a sophisticated Android banking trojan that targets financial applications through advanced phishing techniques. This malware creates convincing fake banking interfaces to steal credentials, intercepts SMS messages to bypass two-factor authentication, and sends sensitive data directly to cybercriminals. In this analysis, we'll examine how Salvador Stealer works and ...

  • web:cds.thalesgroup.com

    The malware uses a two-stage strategy: first, an APK acting as a dropper installs the payload, and then internal phishing tricks users into entering their data. Salvador Stealer intercepts SMS messages to capture verification codes, allowing attackers to bypass two-step authentication systems.

  • web:malpedia.caad.fkie.fraunhofer.de

    Salvador Stealer Propose Change According to ANY.RUN, this is a banking trojan that this collection sensitive user information, including: Registered mobile number, Aadhaar number, PAN card details, Date of birth, and Net banking user ID and password. It uses Telegram as C2.

  • web:malware.news

    In this report, we examine an Android malware sample recently collected and analyzed by our team. This malware masquerades as a banking application and is built to steal sensitive user information. During the analysis, we came across internal references to " Salvador ," so we decided to name it Salvador Stealer .

  • web:outpost24.com

    The KrakenLabs threat intelligence team have taken a deep dive into a malware sample classified as LummaC2.

  • web:www.broadcom.com

    The malware delivery is a multistage process that uses a separate malicious dropper .apk binary responsible for final payload execution. Salvador Stealer aims at collection and exfiltration of user confidential data including banking details and credentials.

  • web:www.pcrisk.com

    What is Salvador Stealer ? Salvador Stealer is malware targeting Android users. It is disguised as a banking application and extracts sensitive information from infected devices. Salvador Stealer sends the stolen details via Telegram Bot API. Victims should scan their devices and eliminate the malware as soon as possible. Salvador Stealer in detail Salvador Stealer is designed to display fake ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.