s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.spybanker

📛 Threat Title

Malware family: SpyBanker

Category: SpyBanker First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.spybanker`. Printable name: SpyBanker.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.spybanker VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.spybanker

IOC database

Type
domain
Value
apk.spybanker
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.spybanker

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.spybanker

References (1)

Remediations (10)

  • web:forum.eset.com

    Hello, I'm trying to do a course/exam online. Website is legit but keeps getting blocked by ESET. I tried calling them and they claim their page is fine. I've tried my best to research it further, but came up short. VirusTotal gives results back as clean, but I do not know how to scan deeper than...

  • web:infoseclabs.io

    Operation Spy Banker uncovers the RTM Group's banking trojan targeting Russian financial institutions. This malware infiltrates systems via legitimate-looking software, enabling unauthorized financial transactions and data theft. Effective countermeasures include network monitoring, behavior analysis, and regular system audits.

  • web:internetprotocol.co

    In a dramatic twist in the ongoing battle against cybercrime, a new wave of Android malware is exploiting the near-field communication (NFC) technology in banking apps, posing a substantial risk to user security and financial integrity. Unraveling the Threat Landscape Breaking into the digital realm with devastating efficiency, these malware variants, including PhantomCard and SpyBanker ...

  • web:labs.k7computing.com

    Interestingly, this Android SpyBanker malware edits the "Call Forward Number" to a hardcoded mobile number, controlled by the attacker, by registering a service called "CallForwardingService" and redirects the user's calls. Incoming calls to the victims when left unattended are diverted to the call forwarded number to carry out any desired malicious activity. This malevolent piece of ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the SpyBanker malware family including references, samples and yara signatures.

  • web:thehackernews.com

    Defend against PhantomCard, SpyBanker , and KernelSU exploits—secure banking, block NFC fraud, and stop Android malware today.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.malwarebytes.com

    Protection Malwarebytes for Android protects against Android/Trojan.Spy.Banker.MYT. Remediation These apps can be uninstalled using the mobile devices uninstall functionality, but these apps can be made available under many names. That is where Malwarebytes for Android can help you, by identifying these apps and removing them.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.pcrisk.com

    What kind of malware is Spy.Banker ? Spy.Banker is a piece of malicious software that targets Android and iOS devices. It is capable of creating app imitations through PWAs (Progressive Web Applications) or WebAPKs; the latter is an Android-only feature wherein Google Chrome automatically generates an APK (referred to as WebAPK).

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.