logo

Godfather Trojan – mobile banking malware that is impossible to refuse

ID: 76f2c9cd-3cd0-5b4f-832f-f55e47c4a8b9

STIX ID: report--76f2c9cd-3cd0-5b4f-832f-f55e47c4a8b9

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2022-12-21

Date Updated: 2026-04-27

...
...

**Godfather** is an actively used Android banking Trojan (an Anubis fork) that targets over 400 international financial services—including banks, crypto wallets, and exchanges—by overlaying web fakes, exfiltrating credentials, notifications, and OTPs, and supporting modules such as VNC, keylogger, screen recording, SOCKS5 proxy, and WebSocket remote control; it is distributed via decoy apps (including Google Play) and Malware-as-a-Service channels, and the report includes multiple IoCs (domains, APK hashes, Telegram channels) and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.