GodFather

MITRE ATT&CK: S1231 View on attack.mitre.org

Aliases: GodFather

First seen
2020-01-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
android
Related IoCs
2 (2 malicious)
Last IoC activity
2026-07-30 13:54:21
Profile updated
2026-07-07 14:07:04

Targeted industries: financial-services

Targeted regions: country_code:tr

Context

GodFather is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and other permissions to evade detection and exfiltrate sensitive data. First identified in 2020, GodFather targets nearly 500 banking applications, cryptocurrency wallets, and exchanges worldwide; however, its virtualization-based attacks have primarily focused on several Turkish financial institutions. This capability enables threat actors to steal banking credentials and other sensitive account information.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to GodFather (S1231). The 2 most recently updated:

TypeIndicatorUpdatedSources
hostname ramcazaka.shop 2026-07-30 1
hostname tajurkoza.com 2026-07-13 1

Malware & tools used

  • Event Triggered Execution (attack-pattern)
  • Virtualization Solution (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Web Protocols (attack-pattern)
  • Impair Defenses (attack-pattern)
  • Native API (attack-pattern)
  • Indicator Removal on Host (attack-pattern)
  • SMS Messages (attack-pattern)
  • Audio Capture (attack-pattern)
  • Contact List (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Prevent Application Removal (attack-pattern)
  • Hooking (attack-pattern)
  • Keylogging (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Scheduled Task/Job (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Abuse Accessibility Features (attack-pattern)
  • Input Injection (attack-pattern)
  • Software Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Call Control (attack-pattern)
  • Phishing (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • SMS Control (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Godfather (report)
  • blog.group-ib.com — Godfather Trojan (report)
  • muha2xmad.github.io — Godfather (report)
  • brandefense.io — Godfather Android Banking Trojan (report)
  • github.com — Strangeloop (report)
  • shindan.io — Godfather Part 1 A Multistage Dropper (report)
  • MITRE ATT&CK — S1231 (report)
  • merklescience.com — The Godfather Android Malware Threat Under The Lens (report)
  • zimperium.com — Your Mobile App Their Playground The Dark Side Of The Virtualization (report)

External references