TF-MAL-apk.gigabud
📛 Threat Title
Malware family: Gigabud
Description
ThreatFox malware family `apk.gigabud`. Printable name: Gigabud.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.gigabud
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.gigabud
IOC database
- Type
- domain
- Value
apk.gigabud- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.gigabud
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.gigabud
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
SUMMARY : An investigation reveals a significant connection between Gigabud and Spynote malware families, targeting over 50 financial apps including banks and cryptocurrency platforms. The campaign utilizes sophisticated distribution methods, including 11 command and control servers and 79 phishing websites impersonating reputable brands.
-
web:cybersecuritynews.com
New Gigabud malware samples have been identified, leveraging the Virbox packer to obfuscate their malicious nature, which employs evasion tactics similar to Golddigger malware , exploiting the zip file format, and abuse significantly hinders detection and analysis by security solutions.
-
web:malpedia.caad.fkie.fraunhofer.de
GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the Asia-Pacific region, specifically Vietnam and Thailand. They utilize social engineering to deliver malware to victims' devices and have close connections to the Gigabud malware family .
-
web:malware.news
Executive Summary On Aug 8th, Cyble shared a blog regarding connections between Gigabud and Golddigger malware campaigns. Through further research, we've uncovered additional details that shed more light on this threat. This blog will discuss a broader range of targeted financial institutions, a stronger link between Spynote and Gigabud , and provide deeper insights into the threat actor's ...
-
web:securityonscreen.com
Zimperium has uncovered new, critical insights into the Gigabud malware campaign, linking it to the notorious Spynote Android RAT.
-
web:www.globalsecuritymag.com
Zimperium has uncovered new, critical insights into the Gigabud malware campaign, linking it to the notorious Spynote Android RAT. First reported by Cyble in August 2024, Zimperium's zLabs investigation reveals that this well-coordinated global campaign leverages phishing websites with intent to install malicious mobile apps from financial institutions. Gigabud manipulates users into ...
-
web:www.group-ib.com
The Group-IB team continued investigating this highly active strain and identified another malware sample within the Gigabud family that doesn't have RAT capabilities - codenamed Gigabud .Loan, which is a fake loan application that exfiltrates user-input data.
-
web:www.infosecurity-magazine.com
Cybersecurity researchers have published a new analysis of the elusive Gigabud banking malware . Originating as an Android Remote Access Trojan (RAT), Gigabud was first observed in September 2022, causing ripples of concern across financial institutions in the Asia-Pacific region. Answering a request ...
-
web:www.prnewswire.com
Why It Matters: The coordination between Gigabud and Spynote illustrates a significant escalation in mobile-targeted malware campaigns, with threat actors targeting financial institutions globally.
-
web:zimperium.com
Gigabud often masquerades as legitimate apps or updates, tricking users into granting it extensive permissions that allow it to intercept and manipulate data. Widespread and targets Several malware samples in the campaign were shielded by a packer known as Virbox, designed to hinder analysis and evade detection by standard malware detection ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Reputation of linked indicators
DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.
| Indicator | Type | Verdict | Score |
|---|---|---|---|
apk.gigabud |
domain | high | 44 |