GodFather
MITRE ATT&CK: S1231 View on attack.mitre.org
Aliases: GodFather
- First seen
- 2020-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-07-30 13:54:21
- Profile updated
- 2026-07-07 14:07:04
Targeted industries: financial-services
Targeted regions: country_code:tr
Context
GodFather is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and other permissions to evade detection and exfiltrate sensitive data. First identified in 2020, GodFather targets nearly 500 banking applications, cryptocurrency wallets, and exchanges worldwide; however, its virtualization-based attacks have primarily focused on several Turkish financial institutions. This capability enables threat actors to steal banking credentials and other sensitive account information.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to GodFather (S1231). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | ramcazaka.shop | 2026-07-30 | 1 |
| hostname | tajurkoza.com | 2026-07-13 | 1 |
Malware & tools used
- Event Triggered Execution (attack-pattern)
- Virtualization Solution (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Web Protocols (attack-pattern)
- Impair Defenses (attack-pattern)
- Native API (attack-pattern)
- Indicator Removal on Host (attack-pattern)
- SMS Messages (attack-pattern)
- Audio Capture (attack-pattern)
- Contact List (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Prevent Application Removal (attack-pattern)
- Hooking (attack-pattern)
- Keylogging (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Scheduled Task/Job (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Abuse Accessibility Features (attack-pattern)
- Input Injection (attack-pattern)
- Software Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Call Control (attack-pattern)
- Phishing (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- SMS Control (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Godfather (report)
- blog.group-ib.com — Godfather Trojan (report)
- muha2xmad.github.io — Godfather (report)
- brandefense.io — Godfather Android Banking Trojan (report)
- github.com — Strangeloop (report)
- shindan.io — Godfather Part 1 A Multistage Dropper (report)
- MITRE ATT&CK — S1231 (report)
- merklescience.com — The Godfather Android Malware Threat Under The Lens (report)
- zimperium.com — Your Mobile App Their Playground The Dark Side Of The Virtualization (report)