s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.luna_spy

📛 Threat Title

Malware family: LunaSpy

Category: LunaSpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.luna_spy`. Printable name: LunaSpy. Aliases: Backdoor.916.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (9)

  • web:cyberpress.org

    A sophisticated new malware campaign has emerged targeting Android smartphone users through messaging platforms, with cybercriminals distributing spyware disguised as legitimate antivirus and banking protection applications. The malicious software, identified as LunaSpy , has been active since at least February 2025 and employs social engineering tactics to trick victims into granting extensive ...

  • web:dataconomy.com

    Upon installation, LunaSpy initiates a simulated virus scan, displaying "threats found" warnings to manipulate users into granting extensive permissions. These requested permissions are not utilized for remediation but rather for malicious activities.

  • web:gbhackers.com

    A sophisticated cybercrime campaign has been discovered targeting Android users through fake antivirus applications that actually deliver LunaSpy spyware to victims' devices. Security researchers have identified this malicious operation as an active threat that exploits users' security concerns to gain unauthorized access to personal data and device functions. The LunaSpy malware campaign ...

  • web:lifehacker.com

    A new spyware campaign, referred to as LunaSpy , is targeting Android users by posing as antivirus delivered via messenger apps. Once installed on your device, it does everything from recording ...

  • web:tadviser.com

    LunaSpy demonstrates high efficiency in monitoring the communication activity of victims. The Trojan monitors correspondence in instant messengers and activity in browsers, intercepts passwords and codes. two-factor authentications The program gets access to the call log and contact list on the infected device, and also reads incoming and ...

  • web:techbriefly.com

    A new Android spyware, dubbed LunaSpy , has been actively circulating since at least February 2025, according to a recent report from Kaspersky. The malicious software primarily spreads through messaging applications like Telegram, often disguised as legitimate antivirus or banking protection software. Upon installation, LunaSpy employs a deceptive tactic: it initiates a fake virus scan ...

  • web:www.androidheadlines.com

    A new LunaSpy spyware has been lurking around since at least February 2025. It pretends to be Android antivirus to steal all your data.

  • web:www.certosoftware.com

    A dangerous spyware campaign is targeting Android users by disguising itself as antivirus or banking protection software. Known as LunaSpy , the malware has been active since at least February 2025 and spreads mainly through popular messaging platforms like Telegram. Cybercriminals send short, convincing messages—often from hacked accounts belonging to someone the victim knows—urging ...

  • web:www.kaspersky.com

    Use Kaspersky for Android to detect spyware and other malware in a timely manner. Trust trusted developers. If someone offers you to download a "new super-accurate and secure" antivirus that the internet seems to know nothing about, be very wary and opt for a proven solution. A bit more on spyware: FinSpy: the ultimate spying tool

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.