s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.exobot

📛 Threat Title

Malware family: ExoBot

Category: ExoBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.exobot`. Printable name: ExoBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.exobot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.exobot

IOC database

Type
domain
Value
apk.exobot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.exobot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.exobot

References (1)

Remediations (10)

  • web:any.run

    Octo malware , also known as ExobotCompact or Coper, is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot . It poses a significant threat to financial institutions, mobile users, and enterprise networks.

  • web:attack.mitre.org

    Exobot Exobot is Android banking malware , primarily targeting financial institutions in Germany, Austria, and France. [1]

  • web:cyberpress.org

    The Exobot malware family , initially a banking trojan, evolved into ExobotCompact in 2019, becoming more compact but retaining key features.

  • web:gbhackers.com

    The Exobot malware family , initially a banking trojan, evolved into ExobotCompact in 2019. In 2021, a new variant, dubbed "Coper," was discovered, which was identified as ExobotCompact, and in 2022, ExobotCompact was rebranded as "Octo."

  • web:lifetips.alibaba.com

    What Is Joker Malware—and Why It's a Critical Efficiency Threat Joker (also tracked as Bread, Anubis, or ExoBot ) is not a single app but a modular, continuously evolving malware family first observed in 2017 and re-emerging in increasingly sophisticated waves through 2024.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the ExoBot malware family including references, samples and yara signatures.

  • web:threatfox.abuse.ch

    ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with apk. exobot . You can also get this data through the ThreatFox API. Database Entry

  • web:www.pcrisk.com

    It must be mentioned that Exobot is a sophisticated malicious program, which complicates both its detection and removal. Exobot malware overview Typically, malware targeting Android OSes abuses the Accessibility Services or Usage Stats to gain control over devices.

  • web:www.securityweek.com

    Threat Fabric security researchers have analyzed an Android banking trojan that allows its operators to perform on-device fraud. Dubbed Octo, the botnet was first mentioned on dark web forums in January 2022, but an analysis of its code revealed a close connection with ExobotCompact, which is believed to be the successor of the Exobot Android trojan, which in turn was based on the source code ...

  • web:www.team-cymru.com

    Coper / Octo - A Conductor for Mobile Mayhem… With Eight Limbs? Analysis of an Android Malware -as-a-Service Operation Coper, a descendant of the Exobot malware family , was first observed in the wild in July 2021, targeting Colombian Android users. At that time, Coper was distributed as a fake version of Bancolombia's "Personas'' application.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.