s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.sharkbot

📛 Threat Title

Malware family: SharkBot

Category: SharkBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.sharkbot`. Printable name: SharkBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.sharkbot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.sharkbot

IOC database

Type
domain
Value
apk.sharkbot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.sharkbot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.sharkbot

References (1)

Remediations (10)

  • web:alluresecurity.com

    Learn how the SharkBot mobile banking Trojan targets financial apps, enabling fraudulent transfers via infected devices.

  • web:attack.mitre.org

    SharkBot is a banking malware , first discovered in October 2021, that tries to initiate money transfers directly from compromised devices by abusing Accessibility Services.

  • web:hunt.io

    Learn about SharkBot , a banking trojan designed to steal login credentials and credit card numbers, facilitating financial fraud on infected computers.

  • web:malpedia.caad.fkie.fraunhofer.de

    SharkBot is a piece of malicious software targeting Android Operating Systems (OSes). It is designed to obtain and misuse financial data by redirecting and stealthily initiating money transfers. SharkBot is particularly active in Europe (United Kingdom, Italy, etc.), but its activity has also been detected in the United States.

  • web:nordvpn.com

    SharkBot is a family of banking trojans for Android devices. SharkBot takes control of the victim's device by exploiting Android accessibility services.

  • web:www.feedzai.com

    Learn how the SharkBot malware disguises itself as a fake antivirus program, captures keystrokes, and allows others to take control of an infected device.

  • web:www.linkedin.com

    🎉 2 new rules added and 263 rules updated for the # Sharkbot malware family . We're moving toward practical, powerful tools — thanks for your continued support! 📎 Report: https://reurl.cc/531l0z

  • web:www.lookout.com

    The malware is now installed under the guise of being an update to the two apps. They use a less sophisticated approach than previously-seen Sharkbot droppers, relying on the user unwittingly allowing the installation of the malicious package rather than attempting to implant the payload onto the user's device automatically.

  • web:www.malwarebytes.com

    Android/Trojan.Bank. SharkBot is a large family of banking Trojans that is actively being developed and quickly adapts to new circumstances. Android/Trojan.Bank. SharkBot is and Android banking Trojan that allows attackers to steal sensitive banking information such as user credentials, personal information, current balance, and even to perform ...

  • web:www.securityweek.com

    Application Security New 'SharkBot' Android Banking Malware Hitting U.S., UK and Italy Targets A new Android banking trojan has been found, targeting international banks from the United Kingdom and Italy (including in the U.S.). and five different cryptocurrency services. Twenty-two instances have been discovered, but more are expected.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.