s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.droidbot

📛 Threat Title

Malware family: DroidBot

Category: DroidBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.droidbot`. Printable name: DroidBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.droidbot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.droidbot

IOC database

Type
domain
Value
apk.droidbot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.droidbot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.droidbot

References (1)

Remediations (10)

  • web:cyberpress.org

    Threat actors behind DroidBot , likely operating from Turkey, have been actively recruiting affiliates through a Telegram channel and sharing details about the malware's capabilities and pricing, occasionally revealing sensitive information like system language and location through inadvertent screenshots.

  • web:cybersecuritynews.com

    DroidBot's malicious operations mostly rely on abusing Accessibility Services.The B4A framework, which is widely used for native Android applications, seems to have been used in the development of DroidBot . It is noteworthy that B4A is frequently utilized in malware created by Brazilian TAs, including the Brata family and its well-known CopyBara variation. The functionalities of the Android ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Cleafy, DroidBot is a modern RAT that combines hidden VNC and overlay attack techniques with spyware-like capabilities, such as keylogging and user interface monitoring. Moreover, it leverages dual-channel communication, transmitting outbound data through MQTT and receiving inbound commands via HTTPS, providing enhanced operation flexibility and resilience.

  • web:thehackernews.com

    As many as 77 banking institutions, cryptocurrency exchanges, and national organizations have become the target of a newly discovered Android remote access trojan (RAT) called DroidBot . " DroidBot is a modern RAT that combines hidden VNC and overlay attack techniques with spyware-like capabilities, such as keylogging and user interface monitoring," Cleafy researchers Simone Mattia, Alessandro ...

  • web:www.cleafy.com

    DroidBot dynamically retrieves the MQTT broker's address from a remote resource to ensure resilience and mitigate takedowns. Specifically, the malware utilises a hardcoded domain within its source code to request an HTTP to a designated endpoint. This endpoint, /GETM5662, returns the broker's address.

  • web:www.enigmasoftware.com

    A new and troubling Android banking threat, known as DroidBot , is making waves by targeting cryptocurrency exchanges and banking apps in the UK, Italy, France, Spain and Portugal. Initially uncovered by cybersecurity researchers in June 2024, DroidBot operates as a Malware -as-a-Service (MaaS) platform, offering its malicious capabilities to affiliates for a hefty $3,000 per month. Despite ...

  • web:www.forbes.com

    DroidBot is a Malware as a Service, available for rental by multiple threat actors. Cleafy says it has identified "17 distinct affiliate groups… multiple affiliates were found to be ...

  • web:www.linkedin.com

    According to a recent report by security researchers at Cleafy, DroidBot is now operating as a malware -as-a-service (MaaS) platform. This model allows affiliate groups to rent the malware and ...

  • web:www.pcrisk.com

    DroidBot overview Similar to other modern Android banking malware , DroidBot abuses Accessibility Services to execute its malicious activities. DroidBot captures screenshots of the victim's device at regular intervals, allowing threat actors to monitor the device's activity in real time.

  • web:www.trolleyesecurity.com

    Details of the Story As reported by Dark Reading, a newly identified Android remote access Trojan (RAT), dubbed DroidBot , has emerged as a new threat. The Trojan, active since mid-2024, combines traditional banking malware tactics with advanced surveillance tools to target banks, cryptocurrency exchanges, and other critical national organizations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.