Researchers reported that the GodFather Android malware is being delivered through a multistage dropper that hides its payload with ZIP header tampering, fake encryption flags, string obfuscation, dead code, and dynamic DEX loading. In the analyzed sample (SHA-256: 49002e994539fa11eab6b7a273cf90272dda43aa3dd9784fde4c23bf3645fdcb), the app com.metaprescutal.systematist extracts an embedded asset containing two encrypted DEX files, decrypts them with a hardcoded DES key, and displays a Turkish-language lure to persuade victims to allow installation of unknown apps. It then side-loads umbras.apk as package com.heb.reb using the Android PackageInstaller session API and launches the installed GodFather core component.
The campaign shows how mobile malware operators are combining layered droppers with virtualization-style abuse and Android permission workarounds to defeat platform protections and increase fraud potential. By installing the payload through session-based mechanisms, the malware is designed to bypass Android 13 Restricted Settings barriers that normally hinder side-loaded apps from gaining sensitive access; once active, the GodFather core seeks Accessibility Service privileges to enable spyware and banking trojan behavior. The broader research warns that this tradecraft turns legitimate mobile app environments into an attacker-controlled execution space, complicating detection for defenders and raising the risk of credential theft and on-device account takeover.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Shindan's analysis states that the more sophisticated GodFather dropper variant it examined was first identified by Zimperium in June. The variant uses a multistage dropper approach designed to bypass Android 13 security restrictions during payload installation.
Shindan published a detailed reverse-engineering report on an Android sample with package name com.metaprescutal.systematist and SHA-256 49002e994539fa11eab6b7a273cf90272dda43aa3dd9784fde4c23bf3645fdcb. The report documented ZIP tampering, staged DEX decryption, and session-based installation of the GodFather payload as com.heb.reb.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.