TF-MAL-apk.wroba
📛 Threat Title
Malware family: Wroba
Description
ThreatFox malware family `apk.wroba`. Printable name: Wroba.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.wroba
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.wroba
IOC database
- Type
- domain
- Value
apk.wroba- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.wroba
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.wroba
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Wroba .
-
web:dl.acm.org
A survey of android malware characterisitics and mitigation techniques. In Proceedings of the 11th International Conference on Information Technology: New Generations (2014), 327-332.
-
web:malpedia.caad.fkie.fraunhofer.de
MoqHao, also called Wroba and XLoader (not to be confused with the malware of the same name for Windows and macOS), is an Android-based mobile threat that is associated with a financially motivated Chinese group called Roaming Mantis. The malware claims to be the default SMS application and has dropper and banker capabilities.
-
web:thehackernews.com
Roaming Mantis spreading updated Wroba mobile malware that hijacks DNS settings of connected Wi-Fi routers for malicious attacks.
-
web:www.bleepingcomputer.com
Starting in September 2022, the 'Roaming Mantis' credential theft and malware distribution campaign was observed using a new version of the Wroba.o/XLoader Android malware that incorporates a ...
-
web:www.kaspersky.com
On January 19, Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the Roaming Mantis campaign. Now cybercriminals can use compromised Wi-Fi routers in cafes, airports hotels and other public places to potentially infect more Android smartphones with the Wroba.o malware . At the moment, the new technique targets users in South Korea, but it can be soon ...
-
web:www.linkedin.com
Wroba (also known as MoqHao, XLoader on Android, or variants like Wroba.o) is a family of Android malware , primarily classified as a banking Trojan and backdoor.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.msspalert.com
The Roaming Mantis cyber threat crew (aka Shaoye) are attacking Wi-Fi routers in public locations to spread Android malware known as Wroba.o.
-
web:www.pcrisk.com
Wroba malware overview Based on our research and analysis, Wroba is designed to infiltrate Android devices - execute malicious commands and steal data from infected systems. This malware begins its operations by gathering information about the mobile device.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.