Bread

MITRE ATT&CK: S0432 View on attack.mitre.org

Aliases: Joker, Bread

Malware type
trojan
Family
Malware family
Operating systems
android
Related IoCs
492 (477 malicious)
Last IoC activity
2026-09-02 03:32:49
Profile updated
2026-07-07 14:04:06

Context

Bread was a large-scale billing fraud malware family known for employing many different cloaking and obfuscation techniques in an attempt to continuously evade Google Play Store’s malware detection. 1,700 unique Bread apps were detected and removed from the Google Play Store before being downloaded by users.

Recent IoC activity

480 malicious indicators in Maltiverse are attributed to Bread (S0432). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname kflk.fburl.fun 2026-09-03 1
hostname joyjo.oss-us-east-1.aliyuncs.com 2026-09-03 1
hostname topldk.cannca.shop 2026-09-03 1
hostname blog.fburl.fun 2026-09-03 1
hostname panel.goepos.id 2026-09-03 1
hostname gapp.oss-ap-southeast-5.aliyuncs.com 2026-09-03 1
hostname beattu.welco.live 2026-09-03 1
hostname chatme.cannca.shop 2026-09-03 1
hostname z7f5b2g-1301476296.cos.ap-mumbai.myqcloud.com 2026-09-03 1
hostname lid.welco.live 2026-09-03 1
hostname glitter.fburl.fun 2026-09-03 1
hostname mystical.oss-ap-southeast-6.aliyuncs.com 2026-09-03 1
hostname dx-ads.s3-website.us-east-2.amazonaws.com 2026-09-03 1
hostname at7kyxx4.net 2026-09-03 1
hostname facy.cannca.shop 2026-09-03 1
hostname studios.welco.live 2026-09-03 1
hostname luha.oss-eu-central-1.aliyuncs.com 2026-09-03 1
hostname wsbb.oss-eu-central-1.aliyuncs.com 2026-09-03 1
hostname oefjgt.cannca.shop 2026-09-03 1
hostname doc.cannca.shop 2026-09-03 1

Malware & tools used

  • Software Packing (attack-pattern)
  • Access Notifications (attack-pattern)
  • SMS Messages (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Generate Traffic from Victim (attack-pattern)
  • Native API (attack-pattern)

Reports & references

  • labs.bitdefender.com — Android Apps And Malware Capitalize On Coronavirus (report)
  • threatfabric.com — Toad Fraud (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • muha2xmad.github.io — Hydra (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Joker (report)
  • security.googleblog.com — Pha Family Highlights Bread And Friends (report)
  • labs.k7computing.com (report)
  • cryptax.medium.com — Live Reverse Engineering Of A Trojanized Medical App Android Joker 632D114073C1 (report)
  • labs.k7computing.com — Joker Unleashes Itself Again On Google Play Store (report)
  • blogs.quickheal.com — Google Play Store Applications Laced With Joker Malware Yet Again (report)
  • hunt.io — Uncovering Joker C2 Network (report)
  • cryptax.medium.com — Tracking Android Joker Payloads With Medusa Static Analysis And Patience 672348B81Ac2 (report)
  • Trend Micro — An Old Jokers New Tricks Using Github To Hide Its Payload (report)
  • research.checkpoint.com — New Joker Variant Hits Google Play With An Old Trick (report)
  • blogs.quickheal.com — Stay Alert Joker Still Making Its Way On Google Play Store (report)
  • Microsoft — Toll Fraud Malware How An Android Application Can Drain Your Wallet (report)
  • web.archive.org — Joker Is Still No Laughing Matter (report)
  • medium.com — Analysis Of Joker A Spy Premium Subscription Bot On Googleplay 9Ad24F044451 (report)
  • MITRE ATT&CK — S0432 (report)

External references