TF-MAL-apk.brata
📛 Threat Title
Malware family: BRATA
Description
ThreatFox malware family `apk.brata`. Printable name: BRATA. Aliases: AmexTroll,Copybara.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.brata
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.brata
IOC database
- Type
- domain
- Value
apk.brata- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.brata
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.brata
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:attack.mitre.org
BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021. Originating in Brazil, BRATA was later also found in the UK, Poland, Italy, Spain, and USA, where it is believed to have targeted financial institutions such as banks.
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as BRATA .
-
web:malpedia.caad.fkie.fraunhofer.de
According to Cleafy, the victim's Android device is factory reset after the attackers siphon money from the victim's bank account. This distracts users from the crime, while removing traces or footprints that might be of interest to forensic analysts.
-
web:rewterz.com
Rewterz Threat Update - BRATA Malware Wipes Devices after Stealing Data - Active IOCs Severity Mediujm Analysis Summary BRATA android malware is equipped with the ability to perform a factory reset on devices and run GPS tracking on them. BRATA became most famous for spying on Brazilian users. Hence the name Brazilian RAT Android ( BRATA ).
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.mcafee.com
BRATA stands for Brazilian Remote Access Tool Android and is a member of an Android malware family . The malware initially targeted users in Brazilvia Google Play and is now making its way through Spain and the United States. BRATA masquerades as an app security scanner that urges users to install fake critical updates to other apps.
-
web:www.researchgate.net
Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...
-
web:www.threatfabric.com
The Brata saga The first appearance of this name dates back to middle of 2019, while this malware family was reported to abuse a CVE in the popular instant messaging application WhatsApp to target victims in Brazil.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.