TF-MAL-apk.phantomlance
📛 Threat Title
Malware family: PhantomLance
Description
ThreatFox malware family `apk.phantomlance`. Printable name: PhantomLance. Aliases: PWNDROID1.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.phantomlance
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.phantomlance
IOC database
- Type
- domain
- Value
apk.phantomlance- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.phantomlance
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.phantomlance
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the PhantomLance malware family including references, samples and yara signatures.
-
web:nwpc-ch.org
Dubbed PhantomLance and active since at least 2015, the ongoing campaign employs a complex piece of spyware designed to harvest victim data. Multiple versions of the malware have been observed, some distributed via malicious applications in Google Play.
-
web:www.bleepingcomputer.com
A malicious campaign dubbed PhantomLance has been targeting users of Android devices with spyware payloads embedded in applications delivered via multiple platforms including Google's Play Store ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.civilsphereproject.org
The campaign involves multiple versions of a malware family they dubbed 'PhantomLance' , some of which were previously analysed, under different names, by Doctor Web and Cylance. Several of the malware instances were found on Google Play, disguised as legitimate apps.
-
web:www.enigmasoftware.com
Security researchers recently discovered a malware campaign targeting Android devices directly through apps in the Google Play Store, which they dubbed PhantomLance . It was revealed that a significant number of apps that were being distributed through the Play Store, as well as other app stores like APKCombo and APKpure were infected with malicious software that was used to spy on people and ...
-
web:www.globalsecuritymag.com
Further research indicated that PhantomLance was mainly distributed on various platforms and marketplaces, including, but not limited to, Google Play and APKpure. To make applications seem legitimate, in almost every case of malware deployment the threat actors tried to build a fake developer profile by creating an associated Github account. In order to evade filtering mechanisms employed by ...
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
-
web:www.scworld.com
A long-running malware campaign whose activity dates back to 2016 has been using a sophisticated playbook of tricks to sneak trojanized Android apps into the Google Play Store as well as third-party marketplaces. Researchers from Kaspersky have dubbed the campaign PhantomLance and, based on certain calling cards, have attributed it with medium ...
-
web:www.wired.com
Malicious Android apps from the so-called PhantomLance campaign targeted hundreds of users, and at least two slipped past Google's defenses.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.