GodFather Malware Targets 500 Banking & Crypto Apps Worldwide
ID: 876695f4-d881-5ec1-8e42-fd2eb8ea10eb
STIX ID: report--876695f4-d881-5ec1-8e42-fd2eb8ea10eb
Feed Name: Cyble Blog
Cyble Research and Intelligence Labs (CRIL) identified a new GodFather Android banking malware variant distributed via phishing APKs (e.g., mygov-au.app) that now uses native code and Accessibility services to target 500 banking and crypto apps across multiple countries; the report includes technical analysis of native functions, C2 retrieval via a Telegram profile (decoding to https://akozamora.top/z.php), observed commands for automated gestures/keylogging, host-stored infection counters/IPs, IOCs (hashes, URLs, domains), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
