TF-MAL-apk.ghostctrl
📛 Threat Title
Malware family: GhostCtrl
Description
ThreatFox malware family `apk.ghostctrl`. Printable name: GhostCtrl.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.ghostctrl
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghostctrl
IOC database
- Type
- domain
- Value
apk.ghostctrl- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.ghostctrl
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghostctrl
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:community.spiceworks.com
A new Android RAT (Remote Access Trojan) detected under the name of GhostCtrl can lock mobile device by resetting their PIN and display a ransom note to infected victims. These ransomware capabilities have been observed in the source code of GhostCtrl , but not in real-world infections, where the RAT was mostly used for its data exfiltration capabilities. Read More
-
web:sos-vo.org
Android malware by the name of " GhostCtrl ", which is a variant of Omni RAT malware , has been launched to target Android, Mac, Windows, and Linux systems in order to snoop on victims' activity and steal sensitive data such as SMS records, contacts, phone numbers, browser bookmarks, searches, and more.
-
web:tdra.gov.ae
Summary As the leading trusted secure cyber coordination center in the region, aeCERT has researched and found about a new malware currently named as " GhostCtrl ". GhostCtrl is an Android backdoor malware that can silently steal information from the device, and can also take control of various device functionalities.
-
web:www.bleepingcomputer.com
A new Android RAT (Remote Access Trojan) detected under the name of GhostCtrl can lock mobile device by resetting their PIN and display a ransom note to infected victims.
-
web:www.computing.co.uk
Trend Micro has raised an alert on new malware called GhostCtrl , which is able to steal all sorts of data from Android phones and is based on OmniRAT. GhostCtrl is a remote access trojan, or RAT ...
-
web:www.eyerys.com
When users download the infected app, the malicious app will repeatedly send users pop-up requests for installation. Overall, GhostCtrl is one of the most advanced Android RATs ever seen. With features that can pose huge damage to victims, it implies that the malware was developed by a threat actor with expertise in Android development.
-
web:www.logitheque.com
The proof with GhostCtrl , an Android malware that has the particularity of taking the appearance of several applications known to deceive its victims.
-
web:www.neowin.net
A new form of Android malware has recently been discovered by Trend Micro, which can not only steal sensitive data from a device, but can also record audio and video without the victim's knowledge.
-
web:www.pindrop.com
A recently discovered piece of Android malware called GhostCtrl apparently evolved from the well-known OmniRAT tool for desktop platforms and has the ability to steal or delete a wide variety of user and device data. GhostCtrl has an interesting pedigree and history. The backdoor is connected to a data-stealing worm known as Retadup that was detected infecting several hospitals in Israel last ...
-
web:www.scworld.com
Researchers have uncovered a highly versatile Android remote access trojan that hijacks device functionality, steals information and can even perform ransomware attacks. The malicious backdoor, dubbed GhostCtrl , is part of a larger campaign that also involves the Windows-based information-stealing worm RETADUP.A, according to Trend Micro, whose res...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.