s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.soumnibot

📛 Threat Title

Malware family: SoumniBot

Category: SoumniBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.soumnibot`. Printable name: SoumniBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.soumnibot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.soumnibot

IOC database

Type
domain
Value
apk.soumnibot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.soumnibot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.soumnibot

References (1)

Remediations (10)

  • web:blackboxsecurity.org

    Additionally, Google Play Protect offers automatic protection against known variants of this malware , even when sourced from external sources. However, the emergence of SoumniBot highlights the ongoing challenges in combating evolving cyber threats and the need for continuous vigilance and innovation in cybersecurity practices.

  • web:blog.netmanageit.com

    Description A new Android banking Trojan called SoumniBot has been discovered targeting Korean users. The malware uses unique obfuscation techniques to evade detection, including exploiting bugs in how the Android manifest file is parsed. Once installed, SoumniBot steals sensitive data like contacts, messages, and banking certificates, and can receive commands from a C2 server.

  • web:quixxi.com

    SoumniBot , a newly identified Android trojan, has been spotted in the open attempting to compromise users in South Korea by exploiting vulnerabilities in the manifest extraction and parsing process. "By obfuscating the Android manifest, the malware is notable for an unconventional method of evading analysis and detection," according to Kaspersky's analyst Dmitry Kalinin highlighted in ...

  • web:rewterz.com

    Analysis Summary An Android trojan named SoumniBot has recently emerged targeting users primarily in South Korea. Its sophisticated approach to evading detection and analysis sets this malware apart, particularly through obfuscation techniques employed within the Android manifest file. The manifest file is a critical component of every Android app which outlines its functionalities permissions ...

  • web:securelist.com

    The developers of SoumniBot unfortunately succeeded due to insufficiently strict validations in the Android manifest parser code. We have detailed the techniques used by this Trojan, so that researchers around the world are aware of the tactics, which other types of malware might borrow in the future.

  • web:techpression.com

    This technique allows SoumniBot to take information from Android phones while avoiding the usual security checks. Researchers from Kaspersky found and studied the virus. They also revealed technical details on how the malware exploits the Android procedure to extract APK manifests.

  • web:thehackernews.com

    New Android malware " SoumniBot " targets users in South Korea by exploiting unique evasion tactics. Find out how it slips through security cracks.

  • web:www.bleepingcomputer.com

    A new Android banking malware named 'SoumniBot' is using a less common obfuscation approach by exploiting weaknesses in the Android manifest extraction and parsing procedure.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.pcrisk.com

    What kind of malware is SoumniBot ? SoumniBot is an Android-specific malware . It utilizes sophisticated anti-analysis and anti-detection techniques. This malicious program is designed to exfiltrate sensitive data from devices, with a particular focus on banking-related information.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.