s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.mysterybot

📛 Threat Title

Malware family: MysteryBot

Category: MysteryBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.mysterybot`. Printable name: MysteryBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.mysterybot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mysterybot

IOC database

Type
domain
Value
apk.mysterybot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.mysterybot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mysterybot

References (1)

Remediations (10)

  • web:androidexperto.com

    MysteryBot is an Android malware family that combines several high-risk attack techniques in one package: banking credential theft, keylogging, screen overlay abuse, and ransomware-style file encryption.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:www.appdome.com

    Mobile malware and Trojans like MysteryBot use overlay attacks to trick users into revealing sensitive information or performing harmful actions inadvertently. Keylogging Prevention - Prevents the use of malicious keyloggers which may be used to intercept two-factor authentication codes or harvest sensitive information.

  • web:www.avira.com

    There is a new malware in town - and it's being targeted at Android users. The app called MysteryBot is still under development and provides everything a criminal inclined person could ever want in one neat little package: It is not only a Banking Trojan but also a keylogger and mobile ransomware.

  • web:www.bleepingcomputer.com

    Cybercriminals are currently developing a new strain of malware targeting Android devices which blends the features of a banking trojan, keylogger, and mobile ransomware.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fortiguard.com

    MysteryBot is a malware that targets Android platform. It contacts C&C servers via HTTP. A remote attacker can issue commands to the malware to perform different operations. All botnet signatures from FortiOS 5.6 onwards are under IPS, and have their default action set to "Block".

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.threatfabric.com

    Conclusion Although certain Android banking malware families such as but not limited to ExoBot 2.5, Anubis II, DiseaseBot have been exploring new techniques to perform overlay attacks on Android 7 and 8, it seems that the actor (s) behind MysteryBot have successfully implemented a workaround solution and have spent some time on innovation.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
1 / 1
IPs scored
0 / 0
Flagged
1
IndicatorTypeVerdictScore
apk.mysterybot domain high 44