s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.ghimob

📛 Threat Title

Malware family: Ghimob

Category: Ghimob First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.ghimob`. Printable name: Ghimob.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.ghimob VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghimob

IOC database

Type
domain
Value
apk.ghimob
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.ghimob

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghimob

References (1)

Remediations (9)

  • web:en.androidsis.com

    A new trojan has been found called Ghimob that infects mobiles to target banking apps to steal data.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Ghimob malware family including references, samples and yara signatures.

  • web:medevel.com

    Is Ghimob Still Active? While Kaspersky's discovery led to awareness and some level of mitigation , Ghimob and similar malware variants remain a looming threat. Malware like Ghimob is often adapted and redeployed with enhancements that make detection even more difficult.

  • web:usa.kaspersky.com

    We recommend that financial institutions watch these threats closely, while improving their authentication processes, boosting anti-fraud technology and threat intelligence data, and trying to understand and mitigate all risks of this new mobile RAT family ." Kaspersky products detect the new family as Trojan-Banker.AndroidOS. Ghimob .

  • web:www.infosecinstitute.com

    Introduction Ghimob is a Trojan malware that is targeting mobile devices around the globe. Kaspersky discovered this piece of malicious software. According to its analysis report, Ghimob can steal data from a total of 153 Android applications, including banks, fintechs, cryptocurrencies and exchanges.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.pcrisk.com

    What is Ghimob ? A banking trojan is a type of malware that cybercriminals use to steal financial information, login credentials from banking-related applications, or other details. Ghimob is the name of a banking trojan targeting Android users in Angola, Brazil (mainly), Germany, Mozambique, Portugal, and some other countries.

  • web:www.sisainfosec.com

    They are warning about a new Android trojan " Ghimob " that can siphon off data from 153 mobile applications. The risk isn't limited to data breach threats - the attackers can even bypass banking institutions' security measures to make fraudulent transactions on Android users' smartphones. With a link in an email that takes the users to an authentic-looking app,… Continue reading ...

  • web:xtncognitivesecurity.com

    Recently a new trojan named Ghimob has been targeting mobile banking apps all around the world. This Remote Access Trojan (RAT) malware aims to steal the victim's banking credentials granting fraudster access to the banking account. The malware can also take control of the device to bypass Strong Customer Authentication (SCA) processes.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.