logo

GodFather Malware Now Targets 500+ Banking and Crypto Apps

ID: c61cfb19-a63c-5072-a602-32ea3e912f6d

STIX ID: report--c61cfb19-a63c-5072-a602-32ea3e912f6d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-11-08

Date Updated: 2026-04-22

Author: do son

...
...

CRIL reports that the GodFather Android malware has evolved into a more evasive native-code variant that targets over 500 banking and cryptocurrency apps worldwide. Distributed via phishing APKs (example: a fake MyGov site), it abuses Android Accessibility services to close legitimate apps, load fake login pages into WebView, perform automated gestures, keylog, and communicate with a C2 server; targeting has expanded geographically beyond its original countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.