Buy/Sell Crypto

Godfather malware targets crypto, banking apps


A piece of malware called “Godfather” is targeting users of crypto apps and other services, according to a statement from German regulator BaFin on Jan. 9.

BaFin said that Godfather affects about 400 cryptocurrency and banking apps. The malware more specifically targets 110 crypto exchanges, 94 crypto wallets, and 215 banking apps, according to a separate report from Group IB in December.

Godfather steals login data from users by displaying fake login windows on top of real ones, thereby deceiving users into entering their data into a monitored form.

Godfather operates only on Android devices. It mimics Google Protect in order to establish itself. It then falsely scans Play Store downloads for malware and hides itself from the list of installed applications. By imitating Google Protect, Godfather can also leverage AccessibilityService to further gain device access and relay data to attackers.

Godfather specifically attempts to imitate applications installed on a user’s device. However, it can also record the screen, launch keyloggers, forward calls containing 2FA codes, send SMS messages, and make use of various other strategies.

Though Germany warned of Godfather attacks today, attacks are not isolated to that country. IB Group said in its report that Godfather has targeted users in 16 countries including the U.S., Turkey, Spain, Canada, France, and the U.K. Incidentally, devices set to use certain languages including Russian cannot run the malware.

Group IB suggested that Godfather was spread partially through a malicious Google Play application. However, the security research group said there is an overall “lack of clarity” on how this particular piece of malware infects devices.

Phishing malware is fairly common. One similar piece of malware called Mars Stealer emerged in 2022, and another called Raccoon was seen in 2021.

However, phishing can be accomplished without infecting user devices. Such attacks can be carried out solely by creating fake emails and websites that resemble their real counterparts — relying on human error rather than compromised devices.

Read Our Latest Market Report



Source

Tags

Share this post:

Share on facebook
Share on twitter
Share on pinterest
Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest Posts

THE ONE AND ONLY WAY TO MAKE MONEY IN AUTOMATIC EASILY!

Receive the whole procedure to be able to follow our signals in less than 2 minutes.

Follow Us

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

To access the VIP channel for free and enjoy the benefits of this exclusive channel, just follow these 3 steps:

1. Open a real account with one of our partner brokers necessarily through these links.

⚠️ Select Standard account

2. Make a deposit of at least €500 (€1000/2000 recommended) or more depending on your capital.

Double bonus as a gift! 🎁

        • 1st deposit: 50% bonus offered!
        • 2nd deposit: 20% bonus offered!

*The bonus will of course be added automatically after your deposit. ✅

3. Once done, you can send us the Screenshot of your deposit to support@signaltrading.cryptalite.com to receive the link of the VIP channel 🚀

(If you already have an account with these different brokers, you need to use another ID with another name + email).

Follow Us

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.