s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.rana

📛 Threat Title

Malware family: Rana

Category: Rana First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.rana`. Printable name: Rana.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.rana VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.rana

IOC database

Type
domain
Value
apk.rana
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.rana

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.rana

References (1)

Remediations (10)

  • web:any.run

    Malware Trends Report 2025: New Security Risks for Businesses in 2026 Summarizing the past year's threat landscape based on activity observed in ANY.RUN's Interactive Sandbox, this annual report provides insights into the most detected malware types, families, TTPs, and phishing threats of 2025.

  • web:attack.mitre.org

    APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities ...

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Rana malware family including references, samples and yara signatures.

  • web:windowsforum.com

    The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fbi.gov

    The FBI has released a new cybersecurity advisory to academic, public, and private sector partners across the country about previously undisclosed malware attributed to Iranian nation state actors.

  • web:www.infoblox.com

    On 17 September, the Federal Bureau of Investigation (FBI) published a new FLASH alert in coordination with the Department of Homeland Security (DHS), and the Department of the Treasury (Treasury).1 The report describes multiple types of malware that the Iranian Rana Intelligence Computing Company - also known as APT39 - has used in their global operations. In the report, the FBI included ...

  • web:www.securityweek.com

    These individuals, the U.S. says, were employed at Rana as managers, programmers, and experts in hacking, offering support for attacks on businesses, institutions, air carriers, and other targets of interest. Hidden behind Rana , the MOIS helped the Iranian government run abuse and surveillance operations against its own citizen. APT39, operating through Rana , leveraged malware for the hacking ...

  • web:www.semanticscholar.org

    This study introduces a robust classification pipeline for distinguishing between multiple malware families and their subgroups using the CIC-MalMem-2022 dataset, which combines high predictive accuracy with model explainability with AI more faster with hybrid hardware usage, making it a viable solution for modern cybersecurity environments. As malware threats continue to evolve in complexity ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.