TF-MAL-apk.monokle
📛 Threat Title
Malware family: Monokle
Description
ThreatFox malware family `apk.monokle`. Printable name: Monokle.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.monokle
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.monokle
IOC database
- Type
- domain
- Value
apk.monokle- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.monokle
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.monokle
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Monokle is targeted, sophisticated mobile surveillanceware. It is developed for Android, but there are some code artifacts that suggests an iOS version may be in development.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:docs.monokle.com
Remediations Remediate issues one by one to achieve zero misconfigurations. Overview The audit pane lists all misconfigurations. This can be seen a TO-DO list of identified issues, helping you tackle each problem one at a time. Monokle Cloud helps ease the process of remediating misconfigurations through problem descriptions, auto-fixes, suppressions, and more. You can use hotkeys within the ...
-
web:malpedia.caad.fkie.fraunhofer.de
Monokle is a sophisticated mobile surveillanceware that possesses remote access trojan (RAT) functionality, advanced data exfiltration techniques as well as the ability to install an attacker-specified certificate to the trusted certificates on an infected device that would allow for man-in-the-middle (MITM) attacks.
-
web:www.bleepingcomputer.com
Citizen Lab reports that the malware appears to be a new version of Monokle , first discovered by Lookout in 2019, which is developed by the St Peterburg-based Special Technology Center, Ltd.
-
web:www.lookout.com
Monokle Mobile Surveillanceware The Monokle surveillanceware family is a well-written and sophisticated piece of mobile malware . One of the most interesting parts of Monokle is that, with root access, it is capable of installing additional attacker-specified certificates to the trusted certificates on an infected device, effectively opening up the target and the device to Man-In-The-Middle ...
-
web:www.pcrisk.com
What kind of malware is Monokle ? Monokle is a spyware-type program that targets Android devices. It is capable of extracting extensive geolocation data, recording calls, reading messages, exfiltrating files, and performing other malicious activities.
-
web:www.penligent.ai
CVE-2026-42897 is an actively exploited Microsoft Exchange Server OWA XSS flaw. Learn what is known, how EEMS and EOMT mitigations work, what to verify, and how defenders should hunt, harden, and prepare for the permanent patch.
-
web:www.securityweek.com
The Monokle malware family can remount the system partition to install attacker certificates, hook itself to appear invisible to Process Manager, retrieve calendar information, get the salt used when storing a user's password, receive messages via keywords delivered via SMS or from designated control phones, interact with office apps, accept ...
-
web:www.wordfence.com
The Wordfence Threat Intelligence Team recently identified an interesting malware family on May 16, 2025 during a site clean. This malware family shared a codebase but varied in features across different versions, including credit card skimming and WordPress credential theft. Most surprisingly, one variant incorporated a live backend system hosted directly on infected websites for attacker use ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.