s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.godfather

📛 Threat Title

Malware family: Godfather

Category: Godfather First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.godfather`. Printable name: Godfather.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.godfather VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.godfather

IOC database

Type
domain
Value
apk.godfather
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.godfather

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.godfather

References (1)

Remediations (10)

  • web:any.run

    The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.

  • web:community.bankofthesierra.com

    Then, in short order: Godfather activates and requests permission under seemingly normal pretenses. It scans the device for financial, crypto, or shopping apps. When a legitimate app is opened, the malware launches it inside a hidden environment. The user logs in as usual, and then the malware records every keystroke.

  • web:imtr.net

    Analysis Summary # Tool/Technique: GodFather Banking Malware ## Overview GodFather is an advanced mobile banking malware that has been upgraded to utilize on-device virtualization. Previously, it functioned by overlaying fake login screens on financial applications.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to PCrisk, Godfather is the name of an Android malware targeting online banking pages and cryptocurrency exchanges in 16 countries. It opens fake login windows over legitimate applications. Threat actors use Godfather to steal account credentials. Additionally, Godfather can steal SMSs, device information, and other data.

  • web:securethinklab.com

    GodFather is an Android malware that was first identified in mid 2023 and quickly attracted the attention of security experts because of its advanced capabilities and modular structure. Its design highlights a significant evolution from its predecessors, exploiting sophisticated techniques to circumvent security measures and infect Android devices.

  • web:undercodetesting.com

    Learning Objectives: Understand how GodFather malware leverages embedded virtualization. Learn detection and mitigation techniques against such attacks. Explore hardening measures for mobile banking applications.

  • web:www.forbes.com

    Hackers want to make you an offer you can't refuse. Android Godfather malware is spreading globally to target more than 500 bank and crypto apps.

  • web:www.infosecurity-magazine.com

    The GodFather banking malware has resurfaced with a dangerous upgrade. Previously known for overlaying fake login screens on financial apps, the malware now uses on-device virtualization to fully hijack legitimate mobile applications and conduct real-time fraud.

  • web:www.pcrisk.com

    GodFather overview Once installed, GodFather imitates the Google Protect tool. While mimicking the Google Protect, it request access to the Accessibility Service. Granting GodFather access to the Accessibility Service allows the malware to access SMSs, contacts, and notifications, and record screen, make calls, and write to external storage.

  • web:www.tomsguide.com

    The Godfather malware has been upgraded with a new ability that allows it to conduct real-time fraud using virtual versions of financial apps.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.