In recent years, Android users have been experiencing a rise in the incidence of the GodFather banking trojan, mainly targeting European users.
This GodFather android malware was discovered in March 2022 and was described as one of the notorious trojans by Cyble Research & Intelligence Labs (CRIL) actively targeting Android bank users all over the world.
There have been several samples of GodFather Android apps found recently that masquerade as MYT applications. MYT Müzik is the name of the application, which is written in Turkish.
Therefore, it appears that this application is targeted at Android users in Turkey who use Android devices. To evade detection by the anti-virus products, the samples analyzed for GodFather were encoded using custom and complex encryption techniques.
Analysts were able to detect that this application had been installed in a manner similar to another legitimate application, and this app disguised itself as MYT Music. There have been more than 10 million downloads of this app from the Google Play Store which is hosted on Google’s servers.
After it has been successfully installed on the victim’s device, the GodFather Android malware achieves the ability to steal the following sensitive data and perform illicit activities:-
Here below we have mentioned the APK metadata:-
There are 23 different permissions that the malware requests from the user, and at least six of those permissions are abused by the malware.
Here is a list of these dangerous permissions:-
Using the code below, the malicious application hides and unhides the icon of the program from the display of the device.
As soon as it receives sunset_cmd from the C&C server of the threat actors, the malware injects HTML phishing pages, and then in the OnAccessibilityEvent method, it constructs an overlay window.
It is from this telegram channel that the malicious application gets the URL of the C&C server:-
It uses this channel in order to communicate with the TAs so that it can receive commands and send the stolen data from the device through this channel.
In order to steal sensitive information from the users’ devices, the malware uses the below commands:-
Here below we have mentioned all the recommendations:-
Penetration Testing As a Service – Download Red Team & Blue Team Workspace
CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…