Bahamut (Android)
- First seen
- 2020-07-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Profile updated
- 2026-07-07 12:54:33
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
According to PCrisk, Bahamut is the name of Android malware with spyware functionality. Threat actors use Bahamut to steal sensitive information. The newest malware version targets various messaging apps and personally identifiable information.
Reports & references
- bellingcat.com — Bahamut Pursuing Cyber Espionage Actor Middle East (report)
- bellingcat.com — Bahamut Revisited Cyber Espionage Middle East South Asia (report)
- Trend Micro — The Urpage Connection To Bahamut Confucius And Patchwork (report)
- Trend Micro — The Urpage Connection To Bahamut Confucius And Patchwork (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Bahamut (report)
- mp.weixin.qq.com — Yaaybjbavxqrqwydg31Bbw (report)
- blackberry.com — Pdfviewer (report)
- ESET — Bahamut Cybermercenary Group Targets Android Users Fake Vpn Apps (report)
- blog.cyble.com — Bahamut Android Malware Returns With New Spying Capabilities (report)