TF-MAL-apk.salvador
📛 Threat Title
Malware family: Salvador Stealer
Description
ThreatFox malware family `apk.salvador`. Printable name: Salvador Stealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.salvador
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.salvador
IOC database
- Type
- domain
- Value
apk.salvador- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.salvador
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.salvador
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Salvador malware distributes as Stealer -as-a-service and targets both individuals and organizations exfiltrating banking credentials.
-
web:anyrun.substack.com
In this report, we examine an Android malware sample recently collected and analyzed by our team. This malware masquerades as a banking application and is built to steal sensitive user information. During the analysis, we came across internal references to " Salvador ," so we decided to name it Salvador Stealer . Real-time visibility into mobile malware behavior is crucial for security teams ...
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as SalvadorStealer .
-
web:blog.gridinsoft.com
Salvador Stealer is a sophisticated Android banking trojan that targets financial applications through advanced phishing techniques. This malware creates convincing fake banking interfaces to steal credentials, intercepts SMS messages to bypass two-factor authentication, and sends sensitive data directly to cybercriminals. In this analysis, we'll examine how Salvador Stealer works and ...
-
web:cds.thalesgroup.com
The malware uses a two-stage strategy: first, an APK acting as a dropper installs the payload, and then internal phishing tricks users into entering their data. Salvador Stealer intercepts SMS messages to capture verification codes, allowing attackers to bypass two-step authentication systems.
-
web:malpedia.caad.fkie.fraunhofer.de
Salvador Stealer Propose Change According to ANY.RUN, this is a banking trojan that this collection sensitive user information, including: Registered mobile number, Aadhaar number, PAN card details, Date of birth, and Net banking user ID and password. It uses Telegram as C2.
-
web:malware.news
In this report, we examine an Android malware sample recently collected and analyzed by our team. This malware masquerades as a banking application and is built to steal sensitive user information. During the analysis, we came across internal references to " Salvador ," so we decided to name it Salvador Stealer .
-
web:outpost24.com
The KrakenLabs threat intelligence team have taken a deep dive into a malware sample classified as LummaC2.
-
web:www.broadcom.com
The malware delivery is a multistage process that uses a separate malicious dropper .apk binary responsible for final payload execution. Salvador Stealer aims at collection and exfiltration of user confidential data including banking details and credentials.
-
web:www.pcrisk.com
What is Salvador Stealer ? Salvador Stealer is malware targeting Android users. It is disguised as a banking application and extracts sensitive information from infected devices. Salvador Stealer sends the stolen details via Telegram Bot API. Victims should scan their devices and eliminate the malware as soon as possible. Salvador Stealer in detail Salvador Stealer is designed to display fake ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.