Bad Behaviour: How to detect banking trojans
ID: 2d6991ee-59b7-5c5f-8163-ae78aeac7733
STIX ID: report--2d6991ee-59b7-5c5f-8163-ae78aeac7733
Feed Name: Group-IB Blog
This Group-IB report analyzes the Godfather Android banking Trojan (a modern Anubis variant) that targets customers of ~400 financial organizations across 16 countries, describing infection vectors (smishing, fake third-party apps), evasion techniques, malicious use of Android accessibility and sensitive permissions, observed behaviors (credential theft, SMS/OTP interception, automated currency conversion and deposits), and indicators such as the observed package name and permission set; it recommends behavior-based detection and fraud-intelligence countermeasures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
