Skip to main content

Threats Tagged 't1541'

View all threats tagged with 't1541'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1541

Threats Tagged 't1541'

Click on any threat for detailed analysis and mitigation recommendations

0

GhostGrab is a sophisticated Android malware that combines cryptocurrency mining with extensive data theft, targeting sensitive financial information such as banking credentials, debit card details, and OTPs. It exploits device resources for mining while maintaining persistence through advanced hiding techniques and resisting removal. The malware abuses permissions to access SMS, calls, and storage, enabling comprehensive data exfiltration. It uses Firebase for command-and-control and data exfiltration, masking malicious activity within legitimate cloud traffic. Its modular design includes WebView-based phishing pages aimed at financial fraud and identity theft. The malware infrastructure involves recently registered domains and obfuscation services, indicating a professional operation. GhostGrab exemplifies the convergence of financial cybercrime and resource exploitation in mobile malware, posing a significant threat to Android users. European organizations with mobile banking users are at risk, especially where Android market share is high. Mitigation requires enhanced mobile security controls, user awareness, and network monitoring for suspicious Firebase traffic.

Join the discussion

Two Android spyware campaigns, ProSpy and ToSpy, have been discovered targeting users in the United Arab Emirates. These campaigns impersonate secure messaging apps like Signal and ToTok, distributing malware through deceptive websites and social engineering tactics. Once installed, the spyware exfiltrates sensitive data including contacts, SMS messages, files, and device information. The campaigns use persistence mechanisms to ensure continuous operation on compromised devices. ProSpy disguises itself as encryption plugins or pro versions of apps, while ToSpy exclusively mimics the ToTok app. The malware is distributed through unofficial sources, highlighting the risks of downloading apps outside official app stores.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: t1541
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses