TF-MAL-apk.defensor_id
📛 Threat Title
Malware family: DEFENSOR ID
Description
ThreatFox malware family `apk.defensor_id`. Printable name: DEFENSOR ID. Aliases: Defensor Digital.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apex.com
The malware's primary function is to request access to an Android device's Accessibility Service, which would allow hackers to execute a variety of commands. For starters, if unwitting users grant access to DEFENSOR ID , the malware can observe any launched apps and send sensitive information back to hackers.
-
web:attack.mitre.org
DEFENSOR ID is a banking trojan capable of clearing a victim's bank account or cryptocurrency wallet and taking over email or social media accounts. DEFENSOR ID performs the majority of its malicious functionality by abusing Android's accessibility service.
-
web:dev.to
The apps named DEFENSOR ID and Defensor Digital rely mainly on Android's Accessibility Service to conduct malicious activities, and go undetected. In fact, a blog post released May 22nd 2020 by malware researcher Lukas Stefanko of ESET states, "the banking trojan was available on Google Play at the time of the analysis.
-
web:hackernoon.com
Android malware apps are nothing new, but this one is of particular interest in how it implements no such functionality that can be readily detected by security products. The apps named DEFENSOR ID and Defensor Digital rely mainly on Android's Accessibility Service to conduct malicious activities, and go undetected.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the DEFENSOR ID malware family including references, samples and yara signatures.
-
web:malwaretips.com
The DEFENSOR ID app made it onto the heavily guarded Google Play store thanks to its extreme stealth. Its creators reduced the app's malicious surface to the bare minimum by removing all potentially malicious functionalities but one: abusing Accessibility Service.
-
web:snyk.io
Shai-Hulud NPM Attack: Remediation with Snyk — Walkthrough of using Snyk to identify compromised packages in your dependency tree and remediate exposure. Summary: indicators of compromise ... Community-maintained detection scripts: GLPMC/Tanstack-Worm-Detector and omarpr/mini-shai-hulud-ioc-scanner (please do verify before using these, though).
-
web:www.enigmasoftware.com
The DEFENSOR ID threat is a newly uncovered banking Trojan, which targets Android devices. The DEFENSOR ID malware was hosted on the official Google Play Store. This malware was masked as a useful application that is meant to boost the security of the device and help the users protect their finances better.
-
web:www.eset.com
Following ESET's notice, Google removed DEFENSOR ID from the official Android app store. "We decided to publish the results of our investigation into this malware to help defenders cope with ultra-low cross-section Android malware .
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.