logo

New Fileless Malware Framework "GhostHook" Targets Android Devices

ID: 05bd4041-28a4-56e3-ae7e-01d4ea00bbec

STIX ID: report--05bd4041-28a4-56e3-ae7e-01d4ea00bbec

Feed Name: iVerify Blog

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

...
...

GhostHook is a recently detected fileless malware distribution framework that hooks browsers and maintains a control connection to deliver malicious payloads via socially engineered URLs, push notifications, and custom landing pages. The report from iVerify details supported browsers and distribution vectors (social media, email, SMS, messaging apps, QR codes), features for hosting/customizing campaigns, and a scenario showing how attackers convert a victim's browser into a controlled "slave" to push downloads and phishing content.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.