Threats Tagged 'coper'
View all threats tagged with 'coper'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'coper'
Click on any threat for detailed analysis and mitigation recommendations
Frogblight is a medium-severity Android banking Trojan primarily targeting users in Turkey. It masquerades as legitimate apps, initially as a court case file viewer and later as common apps like Chrome, to trick victims into installation. The malware steals banking credentials via official government websites and has extensive spyware capabilities, including SMS interception, app enumeration, device info collection, and sending arbitrary SMS messages. It employs advanced persistence and anti-deletion techniques and is distributed mainly through smishing campaigns exploiting legal concerns. Although currently focused on Turkey, its sophisticated remote control features and ongoing development pose risks if it spreads. No CVSS score exists, but the threat impacts confidentiality and integrity significantly with moderate ease of exploitation and no user interaction beyond initial install. European organizations with Turkish-speaking users or business ties should monitor for potential spillover. Mitigations include user education on smishing, app installation restrictions, SMS monitoring, and enhanced mobile endpoint protection. Join the discussion | AlienVault OTX General | 12/15/2025, 13:00:24 UTC Added: 12/15/2025, 17:45:27 UTC |
Anatsa, an Android banking malware first discovered in 2020, has evolved with new capabilities and targets. The latest variant now affects over 831 financial institutions worldwide, including new countries and cryptocurrency platforms. Anatsa has streamlined its payload delivery, implemented DES runtime decryption, and added device-specific restrictions. The malware uses decoy applications in the Google Play Store, some exceeding 50,000 downloads. Alongside Anatsa, 77 other malicious apps from various families were identified, totaling over 19 million installs. Anatsa's evasion techniques include emulation checks, device model verification, and the use of malformed archives to hide malicious code. The malware primarily steals credentials through fake banking login pages tailored to detected financial apps on the user's device. Join the discussion | AlienVault OTX General | 08/22/2025, 23:28:39 UTC Added: 08/25/2025, 11:02:38 UTC |
Showing 1 to 2 of 2 results