GodFather Banking Trojan Debuts Virtualization Tactic
ID: 42449d5b-1a6a-5b8e-b736-979829c9f808
STIX ID: report--42449d5b-1a6a-5b8e-b736-979829c9f808
Feed Name: Dark Reading
Date Published: 2025-06-18
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Zimperium zLabs has reported that the GodFather Android banking Trojan has evolved to use on-device virtualization: a malicious host app installs a controlled sandbox and runs legitimate banking and crypto apps inside it, allowing real-time interception of credentials and bypassing security checks; the campaign currently targets a dozen Turkish financial institutions while scanning hundreds of apps globally, includes advanced evasion (ZIP manipulation, Java-layer code), and comes with published MITRE ATT&CK mappings and IOCs to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
