s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.monokle

📛 Threat Title

Malware family: Monokle

Category: Monokle First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.monokle`. Printable name: Monokle.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.monokle VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.monokle

IOC database

Type
domain
Value
apk.monokle
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.monokle

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.monokle

References (1)

Remediations (10)

  • web:attack.mitre.org

    Monokle is targeted, sophisticated mobile surveillanceware. It is developed for Android, but there are some code artifacts that suggests an iOS version may be in development.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:docs.monokle.com

    Remediations Remediate issues one by one to achieve zero misconfigurations. Overview The audit pane lists all misconfigurations. This can be seen a TO-DO list of identified issues, helping you tackle each problem one at a time. Monokle Cloud helps ease the process of remediating misconfigurations through problem descriptions, auto-fixes, suppressions, and more. You can use hotkeys within the ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Monokle is a sophisticated mobile surveillanceware that possesses remote access trojan (RAT) functionality, advanced data exfiltration techniques as well as the ability to install an attacker-specified certificate to the trusted certificates on an infected device that would allow for man-in-the-middle (MITM) attacks.

  • web:www.bleepingcomputer.com

    Citizen Lab reports that the malware appears to be a new version of Monokle , first discovered by Lookout in 2019, which is developed by the St Peterburg-based Special Technology Center, Ltd.

  • web:www.lookout.com

    Monokle Mobile Surveillanceware The Monokle surveillanceware family is a well-written and sophisticated piece of mobile malware . One of the most interesting parts of Monokle is that, with root access, it is capable of installing additional attacker-specified certificates to the trusted certificates on an infected device, effectively opening up the target and the device to Man-In-The-Middle ...

  • web:www.pcrisk.com

    What kind of malware is Monokle ? Monokle is a spyware-type program that targets Android devices. It is capable of extracting extensive geolocation data, recording calls, reading messages, exfiltrating files, and performing other malicious activities.

  • web:www.penligent.ai

    CVE-2026-42897 is an actively exploited Microsoft Exchange Server OWA XSS flaw. Learn what is known, how EEMS and EOMT mitigations work, what to verify, and how defenders should hunt, harden, and prepare for the permanent patch.

  • web:www.securityweek.com

    The Monokle malware family can remount the system partition to install attacker certificates, hook itself to appear invisible to Process Manager, retrieve calendar information, get the salt used when storing a user's password, receive messages via keywords delivered via SMS or from designated control phones, interact with office apps, accept ...

  • web:www.wordfence.com

    The Wordfence Threat Intelligence Team recently identified an interesting malware family on May 16, 2025 during a site clean. This malware family shared a codebase but varied in features across different versions, including credit card skimming and WordPress credential theft. Most surprisingly, one variant incorporated a live backend system hosted directly on infected websites for attacker use ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.