TF-MAL-apk.bahamut
📛 Threat Title
Malware family: Bahamut
Description
ThreatFox malware family `apk.bahamut`. Printable name: Bahamut.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.bahamut
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.bahamut
IOC database
- Type
- domain
- Value
apk.bahamut- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.bahamut
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.bahamut
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Bahamut .
-
web:malpedia.caad.fkie.fraunhofer.de
Bahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They were observed conduct phishing as well as desktop and mobile malware campaigns.
-
web:thrive.trellix.com
The Anomali Threat Research Team identified a campaign, in which they've assessed with low confidence, what they believe is the work of the Bahamut APT. The campaign targeted victims in what appeared to be a reconnaissance activity to gather machine and user information that may be utilized in future attacks.
-
web:www.cyfirma.com
EXECUTIVE SUMMARY The team at CYFIRMA recently obtained advanced Android malware targeting individuals in the South Asia region. The suspicious Android malware is a dummy chatting app. Our initial technical analyses revealed that APT Bahamut is behind the attack. As technical analyses proceeded further, we also found footprints of tactics used by DoNot APT in the suspicious app belonging to ...
-
web:www.eset.com
Bahamut is frequently described in Arabic mythology as an unimaginably enormous fish. For more technical information about the latest Bahamut APT group campaign, check out the blog post " Bahamut cybermercenary group targets Android users with fake VPN apps " on WeLiveSecurity.
-
web:www.fbi.gov
Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting ...
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.mirror.co.uk
Hacking group 'Bahamut' - based in India and thought to be government-related - is thought to be behind SafeChat which contains malware to target Android users messaging apps to steal data
-
web:www.pcrisk.com
What kind of malware is Bahamut ? Bahamut is the name of Android malware with spyware functionality. Threat actors use Bahamut to steal sensitive information. The newest malware version targets various messaging apps and personally identifiable information. More about Bahamut spyware Once downloaded, installed, and launched, Bahamut asks to enable various permissions and Accessibility Service ...
-
web:www.securityweek.com
A hack-for-hire group known as Bahamut has been targeting Android users with trojanized versions of legitimate VPN applications, ESET reports. An advanced persistent threat (APT) actor focused on cyberespionage, Bahamut was initially detailed in 2017, but continues to be active, leveraging a fake online empir e of social media personas, websites, and applications, which has allowed it to fly ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.