s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.vajraspy

📛 Threat Title

Malware family: VajraSpy

Category: VajraSpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.vajraspy`. Printable name: VajraSpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.vajraspy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.vajraspy

IOC database

Type
domain
Value
apk.vajraspy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.vajraspy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.vajraspy

References (1)

Remediations (9)

  • web:attack.mitre.org

    VajraSpy VajraSpy is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels.

  • web:blog.netmanageit.com

    Description An adversary can leverage a device's cameras to gather information by capturing video recordings. Images may also be captured, potentially in specified intervals, in lieu of video files. Malware or scripts may interact with the device cameras through an available API provided by the operating system. Video or image files may be written to disk and exfiltrated later. This ...

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:infocon.org

    In November 2023, Qihoo 360 independently published an article matching malicious apps described by Meta and this report, attributing them to VajraSpy malware operated by Fire Demon Snake (APT-C-52), a new APT group. Our analysis of these apps revealed that they all share the same malicious code and belong to the same malware family , VajraSpy .

  • web:onlincecybersecure.com

    In November 2023, Qihoo 360 independently published an article matching malicious apps described by Meta and this report, attributing them to VajraSpy malware operated by Fire Demon Snake (APT-C-52), a new APT group. Our analysis of these apps revealed that they all share the same malicious code and belong to the same malware family , VajraSpy .

  • web:redcanary.com

    Extended Berkeley Packet Filter (eBPF) is beginning to transform the Linux malware landscape. Here's what defenders should look out for.

  • web:shad0wmazt3r.github.io

    Vajra Spy - An Android Malware Explore the discovery and analysis of VajraSpy , an Android malware by the Indian APT "Patchwork," designed to exfiltrate data from messaging apps. This blog details my experience with malware analysis and the technical findings from the investigation

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

  • web:www.welivesecurity.com

    Conclusion ESET Research has discovered an espionage campaign using apps bundled with VajraSpy malware conducted, with a high level of confidence, by the Patchwork APT group.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.