GodFather is an Android banking trojan targeting financial-account, identity, and personal information. Active campaigns have targeted hundreds of financial organizations, including banks, cryptocurrency wallets, and exchanges, across North America, Europe, and Turkey. It is distributed through fraudulent applications and malicious websites; observed Turkish activity has used music-themed applications as lures. A multi-stage dropper variant uses session-based package installation to sideload the core payload and help it obtain Android Accessibility Service privileges despite Android restricted-settings protections. GodFather abuses accessibility features to monitor entered text, observe user interactions, operate applications, and interact with device controls. It steals data primarily through keylogging, and can collect contacts, cellular and device details, SMS messages, and push notifications. The malware can record the screen, establish VNC-style remote access, send SMS messages, forward calls, execute USSD requests, enable a proxy service, and use intercepted notifications and SMS messages to circumvent two-factor authentication workflows. It communicates with command-and-control infrastructure using WebSockets, exfiltrates collected information, dynamically obtains targeted-application configurations, and employs runtime string decryption to impede analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon execution, the malware requests activation of its accessibility service under the name of “Müzik”. It is observed that the malware uses accessibility rights to press buttons on the screen, read user inputs such as user clicks, run applications, and monitor what users have typed in a certain text field.
Upon execution, the malware requests activation of its accessibility service under the name of “Müzik”. It is observed that the malware uses accessibility rights to press buttons on the screen, read user inputs such as user clicks, run applications, and monitor what users have typed in a certain text field.
The second stage of the dropper bypasses the Restricted Settings feature added by Google on Android 13... prompting the user to allow installations from unknown sources specifically for this app... Once active, the core program immediately requests Accessibility Service privileges, enabling it to bypass user interaction barriers.
The malware uses the encrypted strings at runtime by decrypting them using the blowfish algorithm.
Upon execution, the malware requests activation of its accessibility service under the name of “Müzik”.
Each file is passed to the decryptFile() function, which handles two key operations: decompression and decryption... Step 1: Decompression (DEFLATE Algorithm)... Step 2: DES Decryption... This decryption step transforms the compressed and encrypted payloads into valid, readable DEX files.
When the user interacts with the AlertDialog... the dropper initiates a new app installation process via the Android PackageInstaller API... session.commit(...).
When the user opens a targeted app, the malware displays a fake or malicious overlay on top of the active window of the targeted app. The opened malicious window is the same as the legitimate app. This allows the attacker to steal sensitive information, such as login credentials, credit card numbers, or other sensitive data, by tricking the user into entering it into the overlay.
Utilizing keylogging, Godfather monitors users’ keystrokes, steals entered data, and tracks user interactions.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
After installing The malware on the device, it checks the device if it’s an emulator or not. If the malware is installed on the emulator, the malware will not run its malicious functions.
QUERY_ALL_PACKAGES gives the app visibility into all installed packages on the device... if ( ! isAppInstalled ( "com.heb.reb" ) ) { showDialog ( ) ; return ; }
The malware will collect information about the device that’s infected and send the collected information to the C2 server . The information which will be sent to the C2 server such as applist which will collect all the applications installed on the device, ag to get the user agent, sim to get the network operator name, phone to get the phone number of the device, model , and ver of the device.
When the user opens a targeted app, the malware displays a fake or malicious overlay on top of the active window of the targeted app. The opened malicious window is the same as the legitimate app. This allows the attacker to steal sensitive information, such as login credentials, credit card numbers, or other sensitive data, by tricking the user into entering it into the overlay.
Utilizing keylogging, Godfather monitors users’ keystrokes, steals entered data, and tracks user interactions.
Godfather can transmit captured data to a command and control server. | Establishing WebSocket connections
AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; BRATA can use both HTTP and WebSockets to communicate with the C2 server; LightSpy has used both HTTPS and Websockets to communicate with the C2.
The malware may also use the VNC connection to install additional malicious software on the device, making it part of a larger network of compromised devices
VNC can be used by the malware to gain remote control over an infected device, allowing the attacker to perform various malicious activities.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile banking malware focused on device takeover and session manipulation to bypass strong authentication controls; heavily targets North America.
Financial-malware family explicitly identified as one of several families used by the actor associated with the StreamRat campaign.
... GodFather ... (v1.0) ...
Banking malware that uses virtualization to mimic legitimate applications (likely to facilitate credential theft and transaction fraud).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.