TF-MAL-apk.ghimob
📛 Threat Title
Malware family: Ghimob
Description
ThreatFox malware family `apk.ghimob`. Printable name: Ghimob.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.ghimob
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghimob
IOC database
- Type
- domain
- Value
apk.ghimob- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.ghimob
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.ghimob
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:en.androidsis.com
A new trojan has been found called Ghimob that infects mobiles to target banking apps to steal data.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Ghimob malware family including references, samples and yara signatures.
-
web:medevel.com
Is Ghimob Still Active? While Kaspersky's discovery led to awareness and some level of mitigation , Ghimob and similar malware variants remain a looming threat. Malware like Ghimob is often adapted and redeployed with enhancements that make detection even more difficult.
-
web:usa.kaspersky.com
We recommend that financial institutions watch these threats closely, while improving their authentication processes, boosting anti-fraud technology and threat intelligence data, and trying to understand and mitigate all risks of this new mobile RAT family ." Kaspersky products detect the new family as Trojan-Banker.AndroidOS. Ghimob .
-
web:www.infosecinstitute.com
Introduction Ghimob is a Trojan malware that is targeting mobile devices around the globe. Kaspersky discovered this piece of malicious software. According to its analysis report, Ghimob can steal data from a total of 153 Android applications, including banks, fintechs, cryptocurrencies and exchanges.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.pcrisk.com
What is Ghimob ? A banking trojan is a type of malware that cybercriminals use to steal financial information, login credentials from banking-related applications, or other details. Ghimob is the name of a banking trojan targeting Android users in Angola, Brazil (mainly), Germany, Mozambique, Portugal, and some other countries.
-
web:www.sisainfosec.com
They are warning about a new Android trojan " Ghimob " that can siphon off data from 153 mobile applications. The risk isn't limited to data breach threats - the attackers can even bypass banking institutions' security measures to make fraudulent transactions on Android users' smartphones. With a link in an email that takes the users to an authentic-looking app,… Continue reading ...
-
web:xtncognitivesecurity.com
Recently a new trojan named Ghimob has been targeting mobile banking apps all around the world. This Remote Access Trojan (RAT) malware aims to steal the victim's banking credentials granting fraudster access to the banking account. The malware can also take control of the device to bypass Strong Customer Authentication (SCA) processes.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.