TF-MAL-apk.moqhao
📛 Threat Title
Malware family: MoqHao
Description
ThreatFox malware family `apk.moqhao`. Printable name: MoqHao. Aliases: Shaoye,Wroba,XLoader.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.moqhao
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.moqhao
IOC database
- Type
- domain
- Value
apk.moqhao- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.moqhao
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.moqhao
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
Description A recent variant of the Android malware MoqHao has been found to automatically execute itself upon installation without requiring user interaction. The malware is distributed via SMS phishing links and abuses legitimate services like URL shorteners and Pinterest. It targets users in Asia and Europe, collects device info, and contains many new command and control capabilities.
-
web:imtr.net
The analysis focuses on the malware family named in the article title, " MoqHao ." ## Activity Summary The article describes the **evolution of MoqHao **, specifically noting that new variants exhibit the behavior of **automatically starting right after installation.**
-
web:malware.news
Authored by Dexter Shin MoqHao is a well-known Android malware family associated with the Roaming Mantis threat actor group first discovered in 2015. McAfee Mobile Research Team has also posted several articles related to this malware family that traditionally targets Asian countries such as Korea and Japan. Recently McAfee Mobile Research Team found that MoqHao began distributing variants ...
-
web:malwaretips.com
MoqHao Android Malware Evolves with Auto-Execution Capability A new variant of MoqHao Android malware silently auto-executes upon installation, snatching data, and hijacking Wi-Fi.
-
web:shadowshell.io
We will also implement YARA rules to detect the malware and Java code to unpack the embedded payload. Executive summary The analyzed sample is an XLoader (also known as MoqHao ) Android banking trojan. It uses a loader APK that decrypts and runs an encrypted DEX payload at runtime.
-
web:www.anomali.com
Anomali Cyber Watch: Volt Typhoon persistence in critical infrastructure and MoqHao variants. Key takeaways, IOCs, and hardening guidance.
-
web:www.cyberswissguards.com
MoqHao malware family is an active malware that has been around for years. Although many years have passed, they are using more and more different ways to hide and reach users. We are seeing a much higher number of C2 commands than in previous, the active use of legitimate sites like Pinterest to store and update phishing data, and code with the potential to target Asian countries like Japan ...
-
web:www.linkedin.com
Threat hunters have identified a new variant of Android malware called MoqHao that automatically executes on infected devices without requiring any user interaction. "Typical MoqHao requires users ...
-
web:www.mcafee.com
Authored by Dexter Shin MoqHao is a well-known Android malware family associated with the Roaming Mantis threat actor group first discovered in 2015.
-
web:www.telekom.com
Moqhao is something like the bestseller from the Roaming Mantis malware family , ready to build a backdoor into your smartphone's Android operating system. This group of Android malware is a proprietary brand of the Yanbian Gang.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.