TF-MAL-apk.soumnibot
📛 Threat Title
Malware family: SoumniBot
Description
ThreatFox malware family `apk.soumnibot`. Printable name: SoumniBot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.soumnibot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.soumnibot
IOC database
- Type
- domain
- Value
apk.soumnibot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.soumnibot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.soumnibot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blackboxsecurity.org
Additionally, Google Play Protect offers automatic protection against known variants of this malware , even when sourced from external sources. However, the emergence of SoumniBot highlights the ongoing challenges in combating evolving cyber threats and the need for continuous vigilance and innovation in cybersecurity practices.
-
web:blog.netmanageit.com
Description A new Android banking Trojan called SoumniBot has been discovered targeting Korean users. The malware uses unique obfuscation techniques to evade detection, including exploiting bugs in how the Android manifest file is parsed. Once installed, SoumniBot steals sensitive data like contacts, messages, and banking certificates, and can receive commands from a C2 server.
-
web:quixxi.com
SoumniBot , a newly identified Android trojan, has been spotted in the open attempting to compromise users in South Korea by exploiting vulnerabilities in the manifest extraction and parsing process. "By obfuscating the Android manifest, the malware is notable for an unconventional method of evading analysis and detection," according to Kaspersky's analyst Dmitry Kalinin highlighted in ...
-
web:rewterz.com
Analysis Summary An Android trojan named SoumniBot has recently emerged targeting users primarily in South Korea. Its sophisticated approach to evading detection and analysis sets this malware apart, particularly through obfuscation techniques employed within the Android manifest file. The manifest file is a critical component of every Android app which outlines its functionalities permissions ...
-
web:securelist.com
The developers of SoumniBot unfortunately succeeded due to insufficiently strict validations in the Android manifest parser code. We have detailed the techniques used by this Trojan, so that researchers around the world are aware of the tactics, which other types of malware might borrow in the future.
-
web:techpression.com
This technique allows SoumniBot to take information from Android phones while avoiding the usual security checks. Researchers from Kaspersky found and studied the virus. They also revealed technical details on how the malware exploits the Android procedure to extract APK manifests.
-
web:thehackernews.com
New Android malware " SoumniBot " targets users in South Korea by exploiting unique evasion tactics. Find out how it slips through security cracks.
-
web:www.bleepingcomputer.com
A new Android banking malware named 'SoumniBot' is using a less common obfuscation approach by exploiting weaknesses in the Android manifest extraction and parsing procedure.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.pcrisk.com
What kind of malware is SoumniBot ? SoumniBot is an Android-specific malware . It utilizes sophisticated anti-analysis and anti-detection techniques. This malicious program is designed to exfiltrate sensitive data from devices, with a particular focus on banking-related information.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.