s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.riltok

📛 Threat Title

Malware family: Riltok

Category: Riltok First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.riltok`. Printable name: Riltok.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.riltok VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.riltok

IOC database

Type
domain
Value
apk.riltok
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.riltok

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.riltok

References (1)

Remediations (9)

  • web:attack.mitre.org

    Riltok Riltok is banking malware that uses phishing popups to collect user credentials. [1]

  • web:halilozturkci.com

    It's serious, but not Conti-level — the Conti leaks included full operational infrastructure, internal chats, affiliate payment systems across multiple malware families. This is a single malware family's construction toolkit. Russia and South Africa targeting The current data confirms India and Russia as active targets.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Riltok malware family including references, samples and yara signatures.

  • web:socprime.com

    The article details a cryptomining campaign involving the redtail malware family , which is delivered through HTTP requests that exploit CVE-2024-4577 in PHP. Threat actors send Base64-encoded payloads that retrieve and run a self-replicating script named cve_2024_4577.selfrep.

  • web:softwaretested.com

    Understand the TikTok Malware , its associated risks, and how to protect yourself with our comprehensive review.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    Updated in May 2023, the joint #StopRansomware Guide includes industry best practices and a response checklist that can serve as an addendum to organization cyber incident response plans specific to ransomware and data extortion.

  • web:www.finextra.com

    Kaspersky researchers have discovered that the money-stealing mobile malware , Riltok has launched new variants and is extending its targeting from Russia to the rest of the world, starting with ...

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.