logo

GodFather Banking Trojan Debuts Virtualization Tactic

ID: 42449d5b-1a6a-5b8e-b736-979829c9f808

STIX ID: report--42449d5b-1a6a-5b8e-b736-979829c9f808

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-06-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Zimperium zLabs has reported that the GodFather Android banking Trojan has evolved to use on-device virtualization: a malicious host app installs a controlled sandbox and runs legitimate banking and crypto apps inside it, allowing real-time interception of credentials and bypassing security checks; the campaign currently targets a dozen Turkish financial institutions while scanning hundreds of apps globally, includes advanced evasion (ZIP manipulation, Java-layer code), and comes with published MITRE ATT&CK mappings and IOCs to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.