s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.badbazaar

📛 Threat Title

Malware family: badbazaar

Category: badbazaar First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.badbazaar`. Printable name: badbazaar.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.badbazaar VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.badbazaar

IOC database

Type
domain
Value
apk.badbazaar
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.badbazaar

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.badbazaar

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    Description Research has identified two campaigns targeting Android users via trojanized Signal and Telegram apps and a malware family that has previously been used to target Uyghurs and other Turkic ethnic minorities.

  • web:cyberpress.org

    The malicious software variants - dubbed MOONSHINE and BADBAZAAR - hide within otherwise legitimate applications through a technique known as "trojanising," enabling covert surveillance of targeted individuals.

  • web:forum.eset.com

    ESET researchers have discovered active campaigns linked to the China-aligned APT group known as GREF, distributing espionage code that has previously targeted Uyghurs

  • web:media.defense.gov

    BADBAZAAR is a mobile malware with iOS and Android variants that have targeted Uyghurs, Tibetans and Taiwanese individuals. This spyware is spread via social media platforms and official app stores.

  • web:threatintelligence.garden.handsomezebra.com

    BadBazaar Description (Lookout) We named this malware family BadBazaar in response to an early variant that posed as a third-party app store titled "APK Bazar." Bazar is a lesser known spelling of Bazaar.

  • web:www.fbi.gov

    BADBAZAAR and MOONSHINE: Spyware targeting Uyghur, Taiwanese and Tibetan groups and civil society actors The NCSC and partners publish new information and mitigation measures for those at high ...

  • web:www.lookout.com

    The BadBazaar malware family is tied to Chinese hacking group APT15. In January 2024, Lookout published an in-depth analysis of the iOS variant of BadBazaar . Previously, Lookout researchers uncovered the Android version in November 2022. BadBazaar , alongside MOONSHINE spyware, have been known to target Tibetan and Uyghur minorities within China.

  • web:www.ncsc.gov.uk

    This advisory provides new and collated threat intelligence on two variants of spyware known as BADBAZAAR and MOONSHINE, and includes advice for app store operators, developers and social media companies to help keep their users safe.

  • web:www.verfassungsschutz.de

    The NCSC and partners publish new information and mitigation measures for those at high risk from two spyware variants.

  • web:www.welivesecurity.com

    FlyGram malware was also seen shared in a Uyghur Telegram group, which aligns with previous targeting of the BadBazaar malware family .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.