s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.ghostctrl

📛 Threat Title

Malware family: GhostCtrl

Category: GhostCtrl First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.ghostctrl`. Printable name: GhostCtrl.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.ghostctrl VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghostctrl

IOC database

Type
domain
Value
apk.ghostctrl
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.ghostctrl

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghostctrl

References (1)

Remediations (10)

  • web:community.spiceworks.com

    A new Android RAT (Remote Access Trojan) detected under the name of GhostCtrl can lock mobile device by resetting their PIN and display a ransom note to infected victims. These ransomware capabilities have been observed in the source code of GhostCtrl , but not in real-world infections, where the RAT was mostly used for its data exfiltration capabilities. Read More

  • web:sos-vo.org

    Android malware by the name of " GhostCtrl ", which is a variant of Omni RAT malware , has been launched to target Android, Mac, Windows, and Linux systems in order to snoop on victims' activity and steal sensitive data such as SMS records, contacts, phone numbers, browser bookmarks, searches, and more.

  • web:tdra.gov.ae

    Summary As the leading trusted secure cyber coordination center in the region, aeCERT has researched and found about a new malware currently named as " GhostCtrl ". GhostCtrl is an Android backdoor malware that can silently steal information from the device, and can also take control of various device functionalities.

  • web:www.bleepingcomputer.com

    A new Android RAT (Remote Access Trojan) detected under the name of GhostCtrl can lock mobile device by resetting their PIN and display a ransom note to infected victims.

  • web:www.computing.co.uk

    Trend Micro has raised an alert on new malware called GhostCtrl , which is able to steal all sorts of data from Android phones and is based on OmniRAT. GhostCtrl is a remote access trojan, or RAT ...

  • web:www.eyerys.com

    When users download the infected app, the malicious app will repeatedly send users pop-up requests for installation. Overall, GhostCtrl is one of the most advanced Android RATs ever seen. With features that can pose huge damage to victims, it implies that the malware was developed by a threat actor with expertise in Android development.

  • web:www.logitheque.com

    The proof with GhostCtrl , an Android malware that has the particularity of taking the appearance of several applications known to deceive its victims.

  • web:www.neowin.net

    A new form of Android malware has recently been discovered by Trend Micro, which can not only steal sensitive data from a device, but can also record audio and video without the victim's knowledge.

  • web:www.pindrop.com

    A recently discovered piece of Android malware called GhostCtrl apparently evolved from the well-known OmniRAT tool for desktop platforms and has the ability to steal or delete a wide variety of user and device data. GhostCtrl has an interesting pedigree and history. The backdoor is connected to a data-stealing worm known as Retadup that was detected infecting several hospitals in Israel last ...

  • web:www.scworld.com

    Researchers have uncovered a highly versatile Android remote access trojan that hijacks device functionality, steals information and can even perform ransomware attacks. The malicious backdoor, dubbed GhostCtrl , is part of a larger campaign that also involves the Windows-based information-stealing worm RETADUP.A, according to Trend Micro, whose res...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.