s1
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.bahamut

📛 Threat Title

Malware family: Bahamut

Category: Bahamut First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.bahamut`. Printable name: Bahamut.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.bahamut VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.bahamut

IOC database

Type
domain
Value
apk.bahamut
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.bahamut

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.bahamut

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Bahamut .

  • web:malpedia.caad.fkie.fraunhofer.de

    Bahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They were observed conduct phishing as well as desktop and mobile malware campaigns.

  • web:thrive.trellix.com

    The Anomali Threat Research Team identified a campaign, in which they've assessed with low confidence, what they believe is the work of the Bahamut APT. The campaign targeted victims in what appeared to be a reconnaissance activity to gather machine and user information that may be utilized in future attacks.

  • web:www.cyfirma.com

    EXECUTIVE SUMMARY The team at CYFIRMA recently obtained advanced Android malware targeting individuals in the South Asia region. The suspicious Android malware is a dummy chatting app. Our initial technical analyses revealed that APT Bahamut is behind the attack. As technical analyses proceeded further, we also found footprints of tactics used by DoNot APT in the suspicious app belonging to ...

  • web:www.eset.com

    Bahamut is frequently described in Arabic mythology as an unimaginably enormous fish. For more technical information about the latest Bahamut APT group campaign, check out the blog post " Bahamut cybermercenary group targets Android users with fake VPN apps " on WeLiveSecurity.

  • web:www.fbi.gov

    Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting ...

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.mirror.co.uk

    Hacking group 'Bahamut' - based in India and thought to be government-related - is thought to be behind SafeChat which contains malware to target Android users messaging apps to steal data

  • web:www.pcrisk.com

    What kind of malware is Bahamut ? Bahamut is the name of Android malware with spyware functionality. Threat actors use Bahamut to steal sensitive information. The newest malware version targets various messaging apps and personally identifiable information. More about Bahamut spyware Once downloaded, installed, and launched, Bahamut asks to enable various permissions and Accessibility Service ...

  • web:www.securityweek.com

    A hack-for-hire group known as Bahamut has been targeting Android users with trojanized versions of legitimate VPN applications, ESET reports. An advanced persistent threat (APT) actor focused on cyberespionage, Bahamut was initially detailed in 2017, but continues to be active, leveraging a fake online empir e of social media personas, websites, and applications, which has allowed it to fly ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.