s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.vultur

📛 Threat Title

Malware family: Vultur

Category: Vultur First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.vultur`. Printable name: Vultur. Aliases: Vulture.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.vultur VT: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/apk.vultur

IOC database

Type
domain
Value
apk.vultur
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.vultur

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/apk.vultur

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    The authors behind Android banking malware Vultur have added new features allowing more remote interaction with victim devices. Vultur encrypts C2 communication, uses multiple encrypted payloads, and disguises as legitimate apps.

  • web:github.com

    Introduction Vultur is an Android banking trojan that emerged in March 2021, distinguishing itself by utilizing screen recording and keylogging to harvest user credentials. Unlike traditional banking malware that employs overlay attacks, Vultur provides attackers with real-time visibility into the victim's device activities.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Vultur malware family including references, samples and yara signatures.

  • web:r3vhunter-research-blog.ghost.io

    The Android banking trojan known as Vultur has resurfaced with a suite of new features and improved anti-analysis and evasion techniques. First identified in early 2021, Vultur leverages Android's accessibility services APIs to execute malicious actions.

  • web:thehackernews.com

    The Android banking trojan known as Vultur has resurfaced with a suite of new features and improved anti-analysis and detection evasion techniques, enabling its operators to remotely interact with a mobile device and harvest sensitive data. " Vultur has also started masquerading more of its malicious ...

  • web:www.bleepingcomputer.com

    Security researchers found a new version of the Vultur banking trojan for Android that includes more advanced remote control capabilities and an improved evasion mechanism.

  • web:www.fox-it.com

    Fox-IT, part of NCC Group, has released an in-depth breakdown of some newly found technical features inside Vultur - a nefarious Android banking malware . It was one of the first Android banking malware families to include screen recording capabilities and contains features such as keylogging and interacting with a victim's device screen.

  • web:www.nccgroup.com

    Examines the evolving Vultur malware , highlighting new remote control features, evasion techniques, and threats to Android banking security.

  • web:www.securityweek.com

    The Android banking malware known as Vultur has been updated with new capabilities, allowing operators to interact with the infected devices and modify files, according to a report from security consulting outfit NCC Group.

  • web:www.sisainfosec.com

    3. Vultur Android banking malware strikes back with refined remote control abilities The Android banking Trojan Vultur has resurfaced with enhanced functionalities and advanced evasion techniques, enabling remote manipulation of mobile devices and data exfiltration.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.