TF-MAL-apk.vajraspy
📛 Threat Title
Malware family: VajraSpy
Description
ThreatFox malware family `apk.vajraspy`. Printable name: VajraSpy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.vajraspy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.vajraspy
IOC database
- Type
- domain
- Value
apk.vajraspy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.vajraspy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.vajraspy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (9)
-
web:attack.mitre.org
VajraSpy VajraSpy is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels.
-
web:blog.netmanageit.com
Description An adversary can leverage a device's cameras to gather information by capturing video recordings. Images may also be captured, potentially in specified intervals, in lieu of video files. Malware or scripts may interact with the device cameras through an available API provided by the operating system. Video or image files may be written to disk and exfiltrated later. This ...
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:infocon.org
In November 2023, Qihoo 360 independently published an article matching malicious apps described by Meta and this report, attributing them to VajraSpy malware operated by Fire Demon Snake (APT-C-52), a new APT group. Our analysis of these apps revealed that they all share the same malicious code and belong to the same malware family , VajraSpy .
-
web:onlincecybersecure.com
In November 2023, Qihoo 360 independently published an article matching malicious apps described by Meta and this report, attributing them to VajraSpy malware operated by Fire Demon Snake (APT-C-52), a new APT group. Our analysis of these apps revealed that they all share the same malicious code and belong to the same malware family , VajraSpy .
-
web:redcanary.com
Extended Berkeley Packet Filter (eBPF) is beginning to transform the Linux malware landscape. Here's what defenders should look out for.
-
web:shad0wmazt3r.github.io
Vajra Spy - An Android Malware Explore the discovery and analysis of VajraSpy , an Android malware by the Indian APT "Patchwork," designed to exfiltrate data from messaging apps. This blog details my experience with malware analysis and the technical findings from the investigation
-
web:www.researchgate.net
Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...
-
web:www.welivesecurity.com
Conclusion ESET Research has discovered an espionage campaign using apps bundled with VajraSpy malware conducted, with a high level of confidence, by the Patchwork APT group.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.