s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.chrysaor

📛 Threat Title

Malware family: Chrysaor

Category: Chrysaor First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.chrysaor`. Printable name: Chrysaor. Aliases: Pegasus,JigglyPuff.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.chrysaor VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.chrysaor

IOC database

Type
domain
Value
apk.chrysaor
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.chrysaor

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.chrysaor

References (1)

Remediations (9)

  • web:android-developers.googleblog.com

    This is known as a targeted attack. In this blog post, we describe Chrysaor , a newly discovered family of spyware that was used in a targeted attack on a small number of Android devices, and how investigations like this help Google protect Android users from a variety of threats. What is Chrysaor ?

  • web:arxiv.org

    We performed our experiments on a public dataset with 9,339 malware samples from 25 different families. Our results show that a mere increase of 7% in the malware size causes an accuracy drop between 25% and 40% for malware family classification.

  • web:attack.mitre.org

    Pegasus for Android is the Android version of malware that has reportedly been linked to the NSO Group. [1] [2] The iOS version is tracked separately under Pegasus for iOS.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Chrysaor malware family including references, samples and yara signatures.

  • web:pages.nist.gov

    To detect malicious applications, use on-device agents that automatically perform signature- and/or behavior-based malware detection. Enterprise To limit the opportunity for an attacker to realize this threat following a security patch for a priviledge escalation vulnerability, ensure timely installation of mobile OS security updates.

  • web:sechub.in

    In this blog post, we describe Chrysaor , a newly discovered family of spyware that was used in a targeted attack on a small number of Android devices, and how investigations like this help Google protect Android users from a variety of threats.

  • web:www.linkedin.com

    Mini Shai-Hulud Malware Returns, Infecting Hundreds of npm Packages and Hijacking Developer Environments Introduction The open-source ecosystem is once again facing a major supply chain security ...

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:zahidaz.github.io

    Unlike iOS Pegasus which used zero-click exploits, Chrysaor used the Framaroot framework for rooting and could persist across factory resets by installing to the /system partition.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.