TF-MAL-apk.xenomorph
📛 Threat Title
Malware family: Xenomorph
Description
ThreatFox malware family `apk.xenomorph`. Printable name: Xenomorph.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.xenomorph
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.xenomorph
IOC database
- Type
- domain
- Value
apk.xenomorph- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.xenomorph
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.xenomorph
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bankingjournal.aba.com
More than 30 U.S. banks have been targeted by a resurgent malware threat. According to a recent advisory by international IT and cybersecurity firm Threat Fabric, Xenomorph malware has reemerged in a new distribution campaign. Threat Fabric's cybersecurity analysts recently identified the resurgence, which relies on deceptive phishing webpages posing as a Chrome update to trick victims into ...
-
web:cybernoz.com
Xenomorph malware is back after months of hiatus and expands the list of targets Pierluigi Paganini September 26, 2023 A new campaign is spreading Xenomorph malware to Android users in the United States, Spain, Portugal, Italy, Canada, and Belgium.
-
web:cybersecuritynews.com
Xenomorph has been discovered with a new malware campaign targeting several United States and Spain institutions. This new campaign shows thousands of downloads of Xenomorph malware by victims.
-
web:heimdalsecurity.com
50,000 Android devices have been infected with Xenomorph malware , spread via Google Play Store to steal financial information.
-
web:malpedia.caad.fkie.fraunhofer.de
Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor.
-
web:securityaffairs.com
" Xenomorph , after months of hiatus, is back, and this time with distribution campaigns targeting some regions that have been historically of interest for this family , like Spain or Canada, and adding a large list of targets from the United States, as well as multiple new Cryptowallets." concludes the report.
-
web:thehackernews.com
Xenomorph is a variant of another banker malware called Alien which first emerged in 2022. Later that year, the financial malware was propagated via a new dropper dubbed BugDrop, which bypassed security features in Android 13.
-
web:www.bleepingcomputer.com
The Xenomorph Android malware has released a new version that adds significant capabilities to conduct malicious attacks, including a new automated transfer system (ATS) framework and the ability ...
-
web:www.infosecurity-magazine.com
Xenomorph malware has reemerged in a new distribution campaign, expanding its scope to target over 30 US banks along with various financial institutions worldwide. Cybersecurity analysts from ThreatFabric recently uncovered this resurgence, which relies on deceptive phishing webpages posing as a Chrome update to trick victims into downloading malicious APKs. Xenomorph first came to the ...
-
web:www.threatfabric.com
Xenomorph is a very advanced malware family , which runs the gamut from simple SMS manipulation to full device control, due to a very powerful Automated Transfer System (ATS) framework obtained via Remote Access capabilities offered by accessibility services privileges. This malware family has been in constant evolution since its discovery in early 2022, adding continuous features over the ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.