s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.brata

📛 Threat Title

Malware family: BRATA

Category: BRATA First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.brata`. Printable name: BRATA. Aliases: AmexTroll,Copybara.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.brata VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.brata

IOC database

Type
domain
Value
apk.brata
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.brata

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.brata

References (1)

Remediations (9)

  • web:attack.mitre.org

    BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021. Originating in Brazil, BRATA was later also found in the UK, Poland, Italy, Spain, and USA, where it is believed to have targeted financial institutions such as banks.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as BRATA .

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Cleafy, the victim's Android device is factory reset after the attackers siphon money from the victim's bank account. This distracts users from the crime, while removing traces or footprints that might be of interest to forensic analysts.

  • web:rewterz.com

    Rewterz Threat Update - BRATA Malware Wipes Devices after Stealing Data - Active IOCs Severity Mediujm Analysis Summary BRATA android malware is equipped with the ability to perform a factory reset on devices and run GPS tracking on them. BRATA became most famous for spying on Brazilian users. Hence the name Brazilian RAT Android ( BRATA ).

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.mcafee.com

    BRATA stands for Brazilian Remote Access Tool Android and is a member of an Android malware family . The malware initially targeted users in Brazilvia Google Play and is now making its way through Spain and the United States. BRATA masquerades as an app security scanner that urges users to install fake critical updates to other apps.

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

  • web:www.threatfabric.com

    The Brata saga The first appearance of this name dates back to middle of 2019, while this malware family was reported to abuse a CVE in the popular instant messaging application WhatsApp to target victims in Brazil.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.