TF-MAL-apk.godfather
📛 Threat Title
Malware family: Godfather
Description
ThreatFox malware family `apk.godfather`. Printable name: Godfather.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.godfather
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.godfather
IOC database
- Type
- domain
- Value
apk.godfather- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.godfather
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.godfather
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.
-
web:community.bankofthesierra.com
Then, in short order: Godfather activates and requests permission under seemingly normal pretenses. It scans the device for financial, crypto, or shopping apps. When a legitimate app is opened, the malware launches it inside a hidden environment. The user logs in as usual, and then the malware records every keystroke.
-
web:imtr.net
Analysis Summary # Tool/Technique: GodFather Banking Malware ## Overview GodFather is an advanced mobile banking malware that has been upgraded to utilize on-device virtualization. Previously, it functioned by overlaying fake login screens on financial applications.
-
web:malpedia.caad.fkie.fraunhofer.de
According to PCrisk, Godfather is the name of an Android malware targeting online banking pages and cryptocurrency exchanges in 16 countries. It opens fake login windows over legitimate applications. Threat actors use Godfather to steal account credentials. Additionally, Godfather can steal SMSs, device information, and other data.
-
web:securethinklab.com
GodFather is an Android malware that was first identified in mid 2023 and quickly attracted the attention of security experts because of its advanced capabilities and modular structure. Its design highlights a significant evolution from its predecessors, exploiting sophisticated techniques to circumvent security measures and infect Android devices.
-
web:undercodetesting.com
Learning Objectives: Understand how GodFather malware leverages embedded virtualization. Learn detection and mitigation techniques against such attacks. Explore hardening measures for mobile banking applications.
-
web:www.forbes.com
Hackers want to make you an offer you can't refuse. Android Godfather malware is spreading globally to target more than 500 bank and crypto apps.
-
web:www.infosecurity-magazine.com
The GodFather banking malware has resurfaced with a dangerous upgrade. Previously known for overlaying fake login screens on financial apps, the malware now uses on-device virtualization to fully hijack legitimate mobile applications and conduct real-time fraud.
-
web:www.pcrisk.com
GodFather overview Once installed, GodFather imitates the Google Protect tool. While mimicking the Google Protect, it request access to the Accessibility Service. Granting GodFather access to the Accessibility Service allows the malware to access SMSs, contacts, and notifications, and record screen, make calls, and write to external storage.
-
web:www.tomsguide.com
The Godfather malware has been upgraded with a new ability that allows it to conduct real-time fraud using virtual versions of financial apps.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.