Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
There were many pieces of evidence in the chat log showing a relationship with malware actions, such as asking to re-encrypt links because Kaspersky was able to detect them.
An algorithm was used to generate a random string for the C&C server URL. The API connection was then initialized, and the hostname of the C&C server was set up.
the Geost operation seems to consist of a large number of APK Android applications related to several topics, from banks and photo services, to fake social networks.
The ApiRequest, ApiResponse, and ApiInterfaceImpl classes enable communication with the C&C server... parameters for commands are appended as JSON format and converted to string.
The botmasters accessed the C&C servers through a web server using port 80/TCP.
The first stage decrypted the second stage file... The aforementioned '.cache' file is renamed to .localsinfotimestamp1494987116 and saved after decryption as ydxwlab.jar, from which the .dex file is loaded and launched.
ClearServiceRunnable takes care of locking/unlocking commands (blocking/unblocking user activity) so the botnet operator can perform remote tasks without user intervention.
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan distributed via unofficial app download pages. It requests device administrator and SMS-related permissions, hides its icon, persists across reboots, decrypts and loads a second stage, communicates with a C2 server, steals SMS, contacts, call logs, installed apps, and banking-related data, can send/intercept SMS, lock the device, open URLs, place calls, and facilitate fraudulent bank transfers.
Geost is a newly identified Android banking trojan/botnet targeting Russian citizens. It infects Android devices via malicious APKs, steals and uploads SMS messages, tracks victim device and banking details, computes account balances from stolen messages, and appears designed to facilitate fraud against multiple Russian and Eastern European banks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.