s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.coper

📛 Threat Title

Malware family: Coper

Category: Coper First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.coper`. Printable name: Coper. Aliases: ExobotCompact,Octo.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.coper VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.coper

IOC database

Type
domain
Value
apk.coper
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.coper

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.coper

References (1)

Remediations (10)

  • web:any.run

    Octo malware , also known as ExobotCompact or Coper , is a sophisticated Android banking trojan that has evolved from earlier malware family Exobot. It poses a significant threat to financial institutions, mobile users, and enterprise networks.

  • web:cyberpress.org

    The Coper /Octo malware family represents a significant and evolving threat to mobile security. Its regional focus, use of fake personas, sophisticated campaign coordination, and global targeting underscore the need for vigilance and robust security measures to protect against such threats.

  • web:cybersecuritynews.com

    The Coper malware , a descendant of the Exobot malware family , was first distributed as a fake version of Bancolombia's 'Personas' application. Fast forwarding to 2022, the malware was discovered, and a lite version of the same malware was advertised on underground forums under the name "Octo Android botnet".

  • web:gbhackers.com

    The Exobot malware family , initially a banking trojan, evolved into ExobotCompact in 2019. In 2021, a new variant, dubbed " Coper ," was discovered, which was identified as ExobotCompact, and in 2022, ExobotCompact was rebranded as "Octo."

  • web:malpedia.caad.fkie.fraunhofer.de

    Coper is an Android banking trojan and RAT descended from ExobotCompact, itself a rewrite of Exobot. It uses a modular architecture, a multi-stage infection chain and (in some variants) a DGA. First observed in Colombia, it has since spread to Europe.

  • web:www.feedzai.com

    Defend your bank against Coper malware with our in-depth threat analysis report. Learn the Trojan's tactics and protect your financial institution's future today.

  • web:www.malwarebytes.com

    Scanning the QR code in the malicious letters leads to a banking Trojan known as Coper , but also referred to as Octo2. Coper is a Malware -as-a-Service which "customers" can spread as they see fit, but they pay for the use of the malicious software and the underlying infrastructure.

  • web:www.pcrisk.com

    What kind of malware is Coper ? Coper is the name of an Android banking Trojan. Our malware researchers discovered that Coper is linked to another Android malware called ExoBotCompat (a reformed version of Exobot). It targets various banking apps. We found that Coper impersonates various banking and utility apps (it uses them as droppers). Coper malware in detail Coper can send Unstructured ...

  • web:www.team-cymru.com

    Coper / Octo - A Conductor for Mobile Mayhem… With Eight Limbs? Analysis of an Android Malware -as-a-Service Operation Coper , a descendant of the Exobot malware family , was first observed in the wild in July 2021, targeting Colombian Android users. At that time, Coper was distributed as a fake version of Bancolombia's "Personas'' application.

  • web:www.zscaler.com

    However, threat actors continue to evolve their tactics and are able to successfully upload dangerous apps laced with malware on the Google play store. Recently, the Zscaler ThreatLabz team discovered apps involving multiple instances of the Joker, Facestealer, and Coper malware families spreading in the virtual marketplace.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.