s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.tianyspy

📛 Threat Title

Malware family: TianySpy

Category: TianySpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.tianyspy`. Printable name: TianySpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.tianyspy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tianyspy

IOC database

Type
domain
Value
apk.tianyspy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.tianyspy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tianyspy

References (1)

Remediations (10)

  • web:attack.mitre.org

    TianySpy is a mobile malware primarily spread by SMS phishing between September 30 and October 12, 2021. TianySpy is believed to have targeted credentials associated with membership websites of major Japanese telecommunication services.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Trend Micro, this malware appears to have been designed to steal credentials associated with membership websites of major Japanese telecommunication services.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.marketscreener.com

    How to protect yourself from phishing This is the first case in Japan where a type of malware that targets iPhones resulted in financial damage. This...

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.notebookcheck.net

    The FBI issued an IC3 FLASH advisory warning of increased malware -enabled ATM jackpotting in the U.S., naming Ploutus malware , sharing IOCs, and outlining mitigation steps.

  • web:www.redpacketsecurity.com

    Trend Micro confirmed a new mobile malware infection chain targeting both Android and iPhone devices. The malware might have been designed to steal credentials associated with membership websites of major Japanese telecommunication services.

  • web:www.scribd.com

    This document provides a summary of a group assignment lab report on mobile malware research based on the MITRE ATT&CK framework. It includes sections that define the MITRE ATT&CK and Cyber Kill Chain frameworks, describe techniques, tactics and procedures, explain the pyramid of pain concept, and analyze several mobile malware examples like TianySpy , AbstractEmu, and Agent Smith. The document ...

  • web:www.trendmicro.com

    The chain is triggered by a smishing message that appears to be sent from a telecommunications company. It is surmised that the malware might have been designed to steal credentials associated with membership websites of major Japanese telecommunication services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.