Trojan.AndroidOS.Bithief is an Android malware family associated in the provided threat intelligence content with botnet command-and-control activity. The content links multiple dangerous domains to this malware, including 99ai.world, uploads.99ai.world, and api.googleapps.top, and classifies those domains under both Botnet C&C and Malware. For api.googleapps.top, the report shows observable infrastructure activity including 27 associated IPv4 addresses, approximately 10 URLs, and about 10 hits. The same domain is reported as created on 22 October 2025, expiring on 22 October 2026, with Cloudflare name servers deborah.ns.cloudflare.com and kip.ns.cloudflare.com. The domains 99ai.world and uploads.99ai.world are also associated with Trojan.AndroidOS.Bithief; the parent domain 99ai.world is reported as created on 15 November 2023, expiring on 15 November 2025, using name servers expirens4.hichina.com and expirens3.hichina.com, and having WHOIS status redemptionperiod. No specific malware capabilities, infection vector, targeted industries, or threat actor attribution are directly provided in the content beyond its association with Android malware and botnet C2 infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The domain is categorized as botnet command-and-control infrastructure associated with Trojan.AndroidOS.Bithief.
The domain is categorized as botnet command-and-control infrastructure associated with Trojan.AndroidOS.Bithief.
Android malware identified in the report context as Trojan.AndroidOS.Bithief and associated with botnet command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.