TF-MAL-apk.badbazaar
📛 Threat Title
Malware family: badbazaar
Description
ThreatFox malware family `apk.badbazaar`. Printable name: badbazaar.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.badbazaar
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.badbazaar
IOC database
- Type
- domain
- Value
apk.badbazaar- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.badbazaar
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.badbazaar
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
Description Research has identified two campaigns targeting Android users via trojanized Signal and Telegram apps and a malware family that has previously been used to target Uyghurs and other Turkic ethnic minorities.
-
web:cyberpress.org
The malicious software variants - dubbed MOONSHINE and BADBAZAAR - hide within otherwise legitimate applications through a technique known as "trojanising," enabling covert surveillance of targeted individuals.
-
web:forum.eset.com
ESET researchers have discovered active campaigns linked to the China-aligned APT group known as GREF, distributing espionage code that has previously targeted Uyghurs
-
web:media.defense.gov
BADBAZAAR is a mobile malware with iOS and Android variants that have targeted Uyghurs, Tibetans and Taiwanese individuals. This spyware is spread via social media platforms and official app stores.
-
web:threatintelligence.garden.handsomezebra.com
BadBazaar Description (Lookout) We named this malware family BadBazaar in response to an early variant that posed as a third-party app store titled "APK Bazar." Bazar is a lesser known spelling of Bazaar.
-
web:www.fbi.gov
BADBAZAAR and MOONSHINE: Spyware targeting Uyghur, Taiwanese and Tibetan groups and civil society actors The NCSC and partners publish new information and mitigation measures for those at high ...
-
web:www.lookout.com
The BadBazaar malware family is tied to Chinese hacking group APT15. In January 2024, Lookout published an in-depth analysis of the iOS variant of BadBazaar . Previously, Lookout researchers uncovered the Android version in November 2022. BadBazaar , alongside MOONSHINE spyware, have been known to target Tibetan and Uyghur minorities within China.
-
web:www.ncsc.gov.uk
This advisory provides new and collated threat intelligence on two variants of spyware known as BADBAZAAR and MOONSHINE, and includes advice for app store operators, developers and social media companies to help keep their users safe.
-
web:www.verfassungsschutz.de
The NCSC and partners publish new information and mitigation measures for those at high risk from two spyware variants.
-
web:www.welivesecurity.com
FlyGram malware was also seen shared in a Uyghur Telegram group, which aligns with previous targeting of the BadBazaar malware family .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.