Godfather Android Trojan Creates Sandbox on Infected Devices

Godfather Android Trojan Creates Sandbox on Infected Devices

A new version of the Godfather Android Trojan deploys a virtualization framework to hijack banking and cryptocurrency apps by running them in a controlled sandbox. This sophisticated technique enables real-time data interception and evasion of detection measures, posing a significant threat to financial security. #GodfatherTrojan #AndroidMalware #BankingApps #CryptocurrencyFraud

Keypoints

  • The Godfather Trojan has been active since June 2021 and targets banking and cryptocurrency apps globally.
  • The malware now uses virtualization tools like Virtualapp and Xposed to run apps in a controlled sandbox environment.
  • It captures user actions in real time, allowing attackers to intercept credentials and sensitive information.
  • The latest version alters APK ZIP files and Android Manifest files to evade detection by security systems.
  • Godfather has been used against Turkish financial institutions and can target nearly 500 different applications across various sectors.

Read More: https://www.securityweek.com/godfather-android-trojan-creates-sandbox-on-infected-devices/