TF-MAL-apk.amextroll
📛 Threat Title
Malware family: AmexTroll
Description
ThreatFox malware family `apk.amextroll`. Printable name: AmexTroll.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.amextroll
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.amextroll
IOC database
- Type
- domain
- Value
apk.amextroll- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.amextroll
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.amextroll
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:cyble.com
Learn how the AMEXTROLL Android banking Trojan is impacting users and how to mitigate the risks associated with this malware .
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the AmexTroll malware family including references, samples and yara signatures.
-
web:threatfox.abuse.ch
ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with apk.brata. You can also get this data through the ThreatFox API. Database Entry
-
web:unsafe.sh
AMEXTROLL , also known as BRATA, was first identified in late June 2021, being distributed through different smishing and phishing campaigns targeting Italian banks. Their last attack was identified in April 2022, when the Threat Actors (TAs) changed the malware's source code to attack specific banking institutions.
-
web:www.breachsense.com
Malware incident response is the coordinated process of identifying, containing, eradicating, and recovering from malware infections. It includes isolating infected systems, analyzing the malware's behavior, remediating affected accounts, and implementing controls to prevent reinfection.
-
web:www.broadcom.com
AMEXTROLL Android banking malware Android banking malware known as AMEXTROLL (also known as Brata) has been spotted in the wild and actively advertised on underground forums, being sold for $3,500 per month. According to reports an actor has been targeting Android users with this threat via phishing websites and disguising it as a security application - a common social engineering tactic these ...
-
web:www.crowdstrike.com
Remediate faster Execute built-in commands or custom scripts to easily carry out complex remediation actions on any managed endpoint remotely. Connect to and quickly isolate the impacted endpoint, then remove malicious files to immediately shut down the attack.
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
-
web:www.threatfabric.com
A varied and wild landscape The mobile malware landscape of the LATAM region, more specifically Brazil, has recently risen to prominence in the news due to families like Brata and Amextroll , extending their reach all the way to Europe. ThreatFabric has already reported in length about these families. However, not all malware developed in South America targets the European market. In fact ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.