s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.phantomlance

📛 Threat Title

Malware family: PhantomLance

Category: PhantomLance First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.phantomlance`. Printable name: PhantomLance. Aliases: PWNDROID1.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.phantomlance VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.phantomlance

IOC database

Type
domain
Value
apk.phantomlance
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.phantomlance

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.phantomlance

References (1)

Remediations (10)

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the PhantomLance malware family including references, samples and yara signatures.

  • web:nwpc-ch.org

    Dubbed PhantomLance and active since at least 2015, the ongoing campaign employs a complex piece of spyware designed to harvest victim data. Multiple versions of the malware have been observed, some distributed via malicious applications in Google Play.

  • web:www.bleepingcomputer.com

    A malicious campaign dubbed PhantomLance has been targeting users of Android devices with spyware payloads embedded in applications delivered via multiple platforms including Google's Play Store ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.civilsphereproject.org

    The campaign involves multiple versions of a malware family they dubbed 'PhantomLance' , some of which were previously analysed, under different names, by Doctor Web and Cylance. Several of the malware instances were found on Google Play, disguised as legitimate apps.

  • web:www.enigmasoftware.com

    Security researchers recently discovered a malware campaign targeting Android devices directly through apps in the Google Play Store, which they dubbed PhantomLance . It was revealed that a significant number of apps that were being distributed through the Play Store, as well as other app stores like APKCombo and APKpure were infected with malicious software that was used to spy on people and ...

  • web:www.globalsecuritymag.com

    Further research indicated that PhantomLance was mainly distributed on various platforms and marketplaces, including, but not limited to, Google Play and APKpure. To make applications seem legitimate, in almost every case of malware deployment the threat actors tried to build a fake developer profile by creating an associated Github account. In order to evade filtering mechanisms employed by ...

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

  • web:www.scworld.com

    A long-running malware campaign whose activity dates back to 2016 has been using a sophisticated playbook of tricks to sneak trojanized Android apps into the Google Play Store as well as third-party marketplaces. Researchers from Kaspersky have dubbed the campaign PhantomLance and, based on certain calling cards, have attributed it with medium ...

  • web:www.wired.com

    Malicious Android apps from the so-called PhantomLance campaign targeted hundreds of users, and at least two slipped past Google's defenses.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.