s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.errorfather

📛 Threat Title

Malware family: ErrorFather

Category: ErrorFather First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.errorfather`. Printable name: ErrorFather.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.errorfather VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.errorfather

IOC database

Type
domain
Value
apk.errorfather
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.errorfather

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.errorfather

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    This report examines a campaign called 'ErrorFather' that utilizes an undetected variant of the Cerberus Android Banking Trojan. The campaign employed a sophisticated multi-stage dropper technique to deploy the malicious payload, which incorporated features like keylogging, overlay attacks, VNC, and a Domain Generation Algorithm (DGA) for ...

  • web:cybersecuritynews.com

    In 2024, a new campaign called " ErrorFather " emerged that has been found using Cerberus' source code with significant modifications. ErrorFather Hackers Attacking Android Users This campaign employs a sophisticated "multi-stage" dropper technique to evade detection.

  • web:cyble.com

    Discover how the ErrorFather campaign deploys the undetected Cerberus Android Banking Trojan to target users. Learn about its sophisticated infection chain, malicious capabilities, and the ongoing cyber threats posed by repurposed malware

  • web:hivepro.com

    THREAT ADVISORY • ATTACK REPORT (Red)3| Attack Details #1The ErrorFather campaign is an advanced Android-targeted cyberattack that repurposes the Cerberus Banking Trojan, a malware originally designed to steal financial data through keylogging, VNC, and overlay attacks.

  • web:malpedia.caad.fkie.fraunhofer.de

    ErrorFather is an Android banking trojan with a multi-stage dropper. The final payload is derived from the Cerberus source code leak.

  • web:nquiringminds.com

    Introduction The ErrorFather campaign represents a sophisticated and evolving threat in the realm of cybercrime, leveraging a modified variant of the Cerberus-based Android Banking Trojan to conduct financial fraud. This campaign, identified by Cyble Research and Intelligence Labs [5], highlights the persistent danger posed by repurposed malware and the innovative techniques employed by ...

  • web:thecyberexpress.com

    The researchers have dubbed the new malware variant " ErrorFather ," named for the Telegram bot the malware communicates with. The new Cerberus variant uses a multi-stage dropper to deploy its payload and can carry out financial fraud through remote attacks, keylogging, and overlay attacks.

  • web:www.broadcom.com

    Cerberus Android banking trojan came to light in 2019, and this variant utilizes a multi-stage dropper to deploy its payload and can execute financial fraud through remote attacks, keylogging, and overlay tactics. The emergence of ErrorFather highlights the persistent danger of repurposed malware , as cybercriminals continue to exploit leaked source code years after the original Cerberus ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.infosecurity-magazine.com

    ErrorFather employs a sophisticated infection chain involving multiple stages (session-based droppers, native libraries, and encrypted payloads), complicating detection and removal efforts. Notably, the campaign utilizes a Telegram bot named 'ErrorFather' to communicate with the malware .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.