Bread
MITRE ATT&CK: S0432 View on attack.mitre.org
Aliases: Joker, Bread
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 492 (477 malicious)
- Last IoC activity
- 2026-09-02 03:32:49
- Profile updated
- 2026-07-07 14:04:06
Context
Bread was a large-scale billing fraud malware family known for employing many different cloaking and obfuscation techniques in an attempt to continuously evade Google Play Store’s malware detection. 1,700 unique Bread apps were detected and removed from the Google Play Store before being downloaded by users.
Recent IoC activity
480 malicious indicators in Maltiverse are attributed to Bread (S0432). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | kflk.fburl.fun | 2026-09-03 | 1 |
| hostname | joyjo.oss-us-east-1.aliyuncs.com | 2026-09-03 | 1 |
| hostname | topldk.cannca.shop | 2026-09-03 | 1 |
| hostname | blog.fburl.fun | 2026-09-03 | 1 |
| hostname | panel.goepos.id | 2026-09-03 | 1 |
| hostname | gapp.oss-ap-southeast-5.aliyuncs.com | 2026-09-03 | 1 |
| hostname | beattu.welco.live | 2026-09-03 | 1 |
| hostname | chatme.cannca.shop | 2026-09-03 | 1 |
| hostname | z7f5b2g-1301476296.cos.ap-mumbai.myqcloud.com | 2026-09-03 | 1 |
| hostname | lid.welco.live | 2026-09-03 | 1 |
| hostname | glitter.fburl.fun | 2026-09-03 | 1 |
| hostname | mystical.oss-ap-southeast-6.aliyuncs.com | 2026-09-03 | 1 |
| hostname | dx-ads.s3-website.us-east-2.amazonaws.com | 2026-09-03 | 1 |
| hostname | at7kyxx4.net | 2026-09-03 | 1 |
| hostname | facy.cannca.shop | 2026-09-03 | 1 |
| hostname | studios.welco.live | 2026-09-03 | 1 |
| hostname | luha.oss-eu-central-1.aliyuncs.com | 2026-09-03 | 1 |
| hostname | wsbb.oss-eu-central-1.aliyuncs.com | 2026-09-03 | 1 |
| hostname | oefjgt.cannca.shop | 2026-09-03 | 1 |
| hostname | doc.cannca.shop | 2026-09-03 | 1 |
Malware & tools used
- Software Packing (attack-pattern)
- Access Notifications (attack-pattern)
- SMS Messages (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Generate Traffic from Victim (attack-pattern)
- Native API (attack-pattern)
Reports & references
- labs.bitdefender.com — Android Apps And Malware Capitalize On Coronavirus (report)
- threatfabric.com — Toad Fraud (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- muha2xmad.github.io — Hydra (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Joker (report)
- security.googleblog.com — Pha Family Highlights Bread And Friends (report)
- labs.k7computing.com (report)
- cryptax.medium.com — Live Reverse Engineering Of A Trojanized Medical App Android Joker 632D114073C1 (report)
- labs.k7computing.com — Joker Unleashes Itself Again On Google Play Store (report)
- blogs.quickheal.com — Google Play Store Applications Laced With Joker Malware Yet Again (report)
- hunt.io — Uncovering Joker C2 Network (report)
- cryptax.medium.com — Tracking Android Joker Payloads With Medusa Static Analysis And Patience 672348B81Ac2 (report)
- Trend Micro — An Old Jokers New Tricks Using Github To Hide Its Payload (report)
- research.checkpoint.com — New Joker Variant Hits Google Play With An Old Trick (report)
- blogs.quickheal.com — Stay Alert Joker Still Making Its Way On Google Play Store (report)
- Microsoft — Toll Fraud Malware How An Android Application Can Drain Your Wallet (report)
- web.archive.org — Joker Is Still No Laughing Matter (report)
- medium.com — Analysis Of Joker A Spy Premium Subscription Bot On Googleplay 9Ad24F044451 (report)
- MITRE ATT&CK — S0432 (report)