TF-MAL-apk.vultur
📛 Threat Title
Malware family: Vultur
Description
ThreatFox malware family `apk.vultur`. Printable name: Vultur. Aliases: Vulture.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.vultur
VT: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/apk.vultur
IOC database
- Type
- domain
- Value
apk.vultur- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.vultur
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/apk.vultur
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
The authors behind Android banking malware Vultur have added new features allowing more remote interaction with victim devices. Vultur encrypts C2 communication, uses multiple encrypted payloads, and disguises as legitimate apps.
-
web:github.com
Introduction Vultur is an Android banking trojan that emerged in March 2021, distinguishing itself by utilizing screen recording and keylogging to harvest user credentials. Unlike traditional banking malware that employs overlay attacks, Vultur provides attackers with real-time visibility into the victim's device activities.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Vultur malware family including references, samples and yara signatures.
-
web:r3vhunter-research-blog.ghost.io
The Android banking trojan known as Vultur has resurfaced with a suite of new features and improved anti-analysis and evasion techniques. First identified in early 2021, Vultur leverages Android's accessibility services APIs to execute malicious actions.
-
web:thehackernews.com
The Android banking trojan known as Vultur has resurfaced with a suite of new features and improved anti-analysis and detection evasion techniques, enabling its operators to remotely interact with a mobile device and harvest sensitive data. " Vultur has also started masquerading more of its malicious ...
-
web:www.bleepingcomputer.com
Security researchers found a new version of the Vultur banking trojan for Android that includes more advanced remote control capabilities and an improved evasion mechanism.
-
web:www.fox-it.com
Fox-IT, part of NCC Group, has released an in-depth breakdown of some newly found technical features inside Vultur - a nefarious Android banking malware . It was one of the first Android banking malware families to include screen recording capabilities and contains features such as keylogging and interacting with a victim's device screen.
-
web:www.nccgroup.com
Examines the evolving Vultur malware , highlighting new remote control features, evasion techniques, and threats to Android banking security.
-
web:www.securityweek.com
The Android banking malware known as Vultur has been updated with new capabilities, allowing operators to interact with the infected devices and modify files, according to a report from security consulting outfit NCC Group.
-
web:www.sisainfosec.com
3. Vultur Android banking malware strikes back with refined remote control abilities The Android banking Trojan Vultur has resurfaced with enhanced functionalities and advanced evasion techniques, enabling remote manipulation of mobile devices and data exfiltration.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.