s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.joker

📛 Threat Title

Malware family: Joker

Category: Joker First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.joker`. Printable name: Joker. Aliases: Bread.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.joker VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.joker

IOC database

Type
domain
Value
apk.joker
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.joker

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.joker

References (1)

Remediations (10)

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as Joker .

  • web:english.mathrubhumi.com

    Google removes 77 malicious apps with over 19 million downloads from Play Store. Protect yourself from Anatsa, Joker , and other malware threats

  • web:lifetips.alibaba.com

    Remove Joker malware -infected Android apps to restore device security and performance. Prevent data theft, reduce battery drain, and eliminate background ad fraud—no root or third-party cleaners needed.

  • web:malpedia.caad.fkie.fraunhofer.de

    Joker is one of the most well-known malware families on Android devices. It manages to take advantage of Google's official app store with the help of its trail signatures which includes updating the virus's code, execution process, and payload-retrieval techniques. This malware is capable of stealing users' personal information including contact details, device data, WAP services, and ...

  • web:trufae.github.io

    Introduction Joker is a notorious Android malware family that first emerged in 2017, notorious for its sophisticated methods of fraud and unauthorized subscription activation. Exploiting vulnerabilities in the Google Play ecosystem, Joker masquerades as legitimate apps to infect devices, exfiltrate sensitive data, and execute background transactions—often without the user's consent. This ...

  • web:www.androidheadlines.com

    Two apps from the 'Joker' family of malware have appeared in October 2023. Those two apps are Love Emoji Messenger (Korsinka Vimoipan) and Beauty Wallpaper HD (fm0989184).

  • web:www.checkpoint.com

    Joker Malware Joker is spyware that collects SMS messages, contact lists, and information about infected devices. Additionally, Joker has the ability to monetize the malware infection by registering the device for premium services without the owner's approval. In October 2022, Joker was the third most common mobile malware behind Anubis and Hydra. Delivered via malicious apps available from ...

  • web:www.huntress.com

    Joker malware is a form of spyware designed to steal sensitive data, such as SMS messages, contact lists, and device information, while silently subscribing users to premium services. Frequently identified under aliases such as " Joker virus" or " Joker trojan," this malware is notorious for masquerading as legitimate apps, such as utilities or entertainment tools, to deceive ...

  • web:www.malwarebytes.com

    Short bio Android/Trojan.Spy. Joker is Malwarebytes' detection name for a family of Android apps that were found to be fleeceware. Type and source of infection Android/Trojan.Spy. Joker is fleeceware. Fleeceware is a type of malware for mobile devices that comes with hidden, excessive subscription fees. Android/Trojan.Spy. Joker was initially distributed through both Google Play store. After ...

  • web:www.pcrisk.com

    What is Joker malware ? Joker (also known as SysJoker) is a malware Trojan that targets Android users. It was packaged in at least two dozen applications that were downloaded from Google Play store over 400,000 times. The main purpose of Joker is to generate revenue for the cyber criminals responsible through fraudulent advertising activities. If an application installed on an Android device ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.