TF-MAL-apk.hydra
📛 Threat Title
Malware family: Hydra
Description
ThreatFox malware family `apk.hydra`. Printable name: Hydra.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.hydra
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.hydra
IOC database
- Type
- domain
- Value
apk.hydra- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.hydra
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.hydra
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.fox-it.com
The features implemented in this banking malware are present in most of the banking malware families: injections/overlays, keylogging (listening to Accessibility events) and, since June 2022, Hydra has even introduced a cookie-stealing feature which targeted several banking entities in Spain.
-
web:hunt.io
Discover the evolution, capabilities, and mitigation strategies of Hydra , the Android banking trojan targeting users globally since 2019.
-
web:malwaretips.com
This guide teaches you how to remove HYDRA ransomware virus for free by following easy step-by-step instructions.
-
web:muha2xmad.github.io
Anti-emulator I tried to run the sample in the emulator such as android studio and intercept the traffic between the malware and the C2 server with Burp suite. But It didn't go as well as my last analysis of a previous sample of Hydra on my twitter. Then I used our magic tool droidlysis to get the Properties of the payload KCFj.json.
-
web:www.bridewell.com
Executive Summary Bridewell Cyber Threat Intelligence has identified a new campaign by the Hydra android banking trojan, beginning in late-January that is still ongoing, targeting users of banking applications on android by impersonating Google Chrome and the Google Play Store in Spain and Latin America. Bridewell has identified 28 Hydra Command-and-Control (C2) servers in the wild, some of ...
-
web:www.checkpoint.com
Learn what Hydra malware is, and how companies can protect themselves, their employees, and their devices against this mobile malware .
-
web:www.feedzai.com
Hydra malware steals banking credentials, credit card information, and sensitive data. Download this report to learn how to protect your bank and customers from Hydra .
-
web:www.linkedin.com
Abstract This white paper presents a comprehensive analysis of Hydra , a sophisticated and modular malware that has been utilized in targeted attacks against financial institutions and high-profile ...
-
web:www.nccgroup.com
Decompiled code used to send the stolen credentials to the C2 server Keylogging: Hydra abuses the Accessibility permissions to set up an Accessibility service that receives every Accessibility event happening on the infected device. This way the malware receives change events for TextFields (to steal usernames and passwords) and button clicks. Keylogger code In order to complement the ...
-
web:www.pcrisk.com
What kind of malware is Hydra ? Hydra is an Android banking Trojan targeting customers of Commerzbank, a major German bank. After downloading and opening the malicious app, it requests certain permissions. It starts its malicious activities after receiving those permissions. It is known that threat actors used Google Play Store to distribute Hydra by disguising it as a PDF document manager ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.