A new version of the Godfather Android Trojan deploys a virtualization framework to hijack banking and cryptocurrency apps by running them in a controlled sandbox. This sophisticated technique enables real-time data interception and evasion of detection measures, posing a significant threat to financial security. #GodfatherTrojan #AndroidMalware #BankingApps #CryptocurrencyFraud
Keypoints
- The Godfather Trojan has been active since June 2021 and targets banking and cryptocurrency apps globally.
- The malware now uses virtualization tools like Virtualapp and Xposed to run apps in a controlled sandbox environment.
- It captures user actions in real time, allowing attackers to intercept credentials and sensitive information.
- The latest version alters APK ZIP files and Android Manifest files to evade detection by security systems.
- Godfather has been used against Turkish financial institutions and can target nearly 500 different applications across various sectors.
Read More: https://www.securityweek.com/godfather-android-trojan-creates-sandbox-on-infected-devices/