Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Godfather

173
Global rank
191 infographic chevron month
Month rank
178 infographic chevron week
Week rank

The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.

Trojan
Type
Unknown
Origin
1 December, 2022
First seen
14 May, 2026
Last seen

How to analyze Godfather with ANY.RUN

Type
Unknown
Origin
1 December, 2022
First seen
14 May, 2026
Last seen

IOCs

IP addresses
149.154.167.99
142.251.127.84
142.251.127.81
142.251.154.119
142.250.154.102
142.251.110.94
192.178.183.94
142.251.14.97
192.178.183.95
142.251.127.92
216.239.35.0
142.251.127.101
142.251.13.138
142.251.13.119
142.251.150.119
142.251.13.139
216.239.34.36
142.251.155.119
142.251.152.119
142.250.154.113
Hashes
c8a25c6e88da3534074b2a689bd128683d1548c24c0b0372530cfae61d81d907
24f6099070e23828c6d2d89bc653e2bb2ace74b769f33ca7def5050e2c361c33
a4b0e4992464a105e8545fc796e3e0a2d769c143f15483988e542b1906e40f78
e495ecad3d59b70a6daf8d8a28691d649f8aa4f60d35321d9150f0f4c03d38ca
f29a09a24bbf97617c0db01f19d01be607857e0bb58117556e90390de4576216
9fe045cf78165009af73afa6da87b3db66e81f02d6468908d9ee85270479af88
c270e5eec4b009ee00aa909324aa56dfd0fb0629278d06c24f238ee42cbdc9a3
d019bc3b764f8ae8001406ac943136cf0d85da5a39a80e7ab9f9825723cd5435
23fad8c3189545275f333cea63af0c86107797fc881ed4dbaca0eb807d906ffe
d101d6b3a9cc0771de2a7e8f28626ace7af17f732001318bd14d4250881d5567
4dc64aab27808486950d9e6be1fa7b6a8b790bc8824ab0e0cd442f0506d0d886
1b790a4b22ce578b6e9dee1831fbdefc334d13b1549baab1cb0231c3fa8b74b8
6f6f526c8d5f85d6dd52064a083eb26236e704d3ddaa06373a4d3d99d57da393
36a9e7f1c95b82ffb99743e0c5c4ce95d83c9a430aac59f84ef3cbfab6145068
502e9680cfa78fa8be779cbf4f1947c8eaa3d43bf8c7464800ec772b2ddea358
317e5fdaa14e548c0045d5e662709cfe0b692e0384a8396cf22054bf0a1e1c48
a11fbbb463461087e3e1522f0e58f0bb1020a54b741cf493dbd6e0ce3923d811
95d4300578446bf713fcf326ded94be0c3dc337a488dad7b1216220c5a099240
b704ce6c3a3b851f8187ea7f11fb41482f0241581e9a90f152323fc067a23c9a
9b21821b058164f8fbbd7c68fc4e2e5d175b5eb286dd7111c8a2b5be247f614c
Domains
staging-remoteprovisioning.sandbox.googleapis.com
accounts.google.com
www.google-analytics.com
apis.google.com
play-lh.googleusercontent.com
fonts.gstatic.com
time.android.com
payments.google.com
www.google.com
t.me
clients2.google.com
ssl.gstatic.com
google.com
www.googletagmanager.com
play.google.com
connectivitycheck.gstatic.com
www.gstatic.com
content-autofill.googleapis.com
region1.google-analytics.com
play.googleapis.com
URLs
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnivb_n4bilsty9h4qsp8ymafocvzk8gxr4c=&request_id=5c55b0f2-46d7-4d12-80dd-990163fdadb7
https://t.me/tumonokasiperake
http://clients2.google.com/time/1/current?cup2key=9:6jvtbp92njq1umro_buoceo292t07i9qoho8rjf6clw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://play.google.com/store/apps/details?id=com.lmr.lfm
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&laf=b64bin&json=standard
https://play.google.com/store/apps/details?id=com.lmr.lfm
https://fonts.gstatic.com/s/i/productlogos/avatar_anonymous/v4/web-32dp/logo_avatar_anonymous_color_1x_web_32dp.png
https://play-lh.googleusercontent.com/etayirtbvmjan2opqqnr0l76gczlbhfmegbl2nsjvchwiiyeoirk3a9ptfttpuzblea=w240-h480-rw
https://play-lh.googleusercontent.com/jyizb7tsazchgss7holbnkfmlbh-mln_11hdn8483vgxoebp7aqwnhnho4jtgj4yo53z7vvarewjbqmzzg=w48-h16-rw
https://play-lh.googleusercontent.com/jyizb7tsazchgss7holbnkfmlbh-mln_11hdn8483vgxoebp7aqwnhnho4jtgj4yo53z7vvarewjbqmzzg=s38-rw
https://play-lh.googleusercontent.com/22s8sy20xho69ircmeczqnfimghlbnlut_ia4a_vbpyzwl0feqs_22oispxqp9cy2sa=w526-h296-rw
https://play-lh.googleusercontent.com/qgze6_-elo3fn-mr1qddreoolm5tdqiq0iwaah6janrikrtykw4bnr-23ieqxybckrk=w526-h296-rw
https://play-lh.googleusercontent.com/zfmd0o-jtmmpmkdlkp5bcqubdvteek4pmgbbjnlpnyi5g5rumuyyypvqi82lozd-vw=w526-h296-rw
https://play-lh.googleusercontent.com/qkcna2kprwpndttvel6ctgbxlxflgdd0u6ridgg08gxshcmslyfam7alvjdkt7m0y2u=w526-h296-rw
https://play-lh.googleusercontent.com/ifstqoxdeluvv4t3kxkxp3otcufvwf5zqqjt7aixy4n2uavigccykxeg6ezv9fq10x1itpj1oorm=s20-rw
https://play-lh.googleusercontent.com/12usw7aflgz466ifdehktnmoaep_vhxdmkj6jebodzwcsefoc-thrx14mqe0r8kf9xczrpmqjts=s20-rw
https://play-lh.googleusercontent.com/w5dptvb8fhmkn5lbfzki_ohl3zi1rdc-aful19uk4f7np2nmjle5qqud6h0haeej977u3wh4yaq=s20-rw
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 1389
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 3845
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 5997
comments 0

What is Godfather malware?

Godfather is a rebranded and evolved variant of the Anubis trojan, first identified in 2022. It primarily targets Android devices, exploiting their accessibility services and employing innovative techniques such as on-device virtualization to hijack legitimate apps. This malware is designed to steal sensitive information, including banking credentials, two-factor authentication codes, and cryptocurrency wallet data.

It mimics legitimate applications and uses advanced obfuscation techniques to avoid detection. Once installed, it overlays fake login screens on top of banking and cryptocurrency apps to harvest user credentials. Godfather is actively maintained and frequently updated, making it a persistent and evolving threat.

It employs a number of vectors of system infiltration and spread:

  • Disguised as legitimate apps in third-party app stores or even Google Play (later removed)
  • Delivered via smishing (malicious SMS)
  • Embedded in phishing websites
  • Spread through social engineering campaigns
  • Sometimes distributed through cracked or modded APKs.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Godfather Victimology

Godfather primarily targets users in Europe, the U.S., and Canada, but its campaigns have also affected regions in Asia and the Middle East.

Both individual consumers and businesses, particularly those with mobile banking operations or cryptocurrency holdings, are at risk. Enterprises with employees using personal devices for corporate access (BYOD) are especially vulnerable due to the malware’s ability to compromise mobile endpoints.

What Godfather Can Do to User Device

Once installed, Godfather can severely compromise an Android device by:

  • Stealing Data: Captures SMS, contacts, login credentials, and two-factor authentication codes.
  • Screen Control: Uses Virtual Network Computing (VNC) to control the device screen remotely.
  • Keylogging: Records keystrokes to steal PINs and passwords.
  • Preventing Removal: Abuses accessibility services to block uninstallation attempts.
  • Push Notification Manipulation: Sends fake notifications to trick users into revealing sensitive information.

How Godfather Threatens Businesses and Organizations

Similar to other Android malware like Salvador Stealer and Spynote, Godfather can be used to:

  • Compromise corporate accounts and credentials
  • Steal funds or initiate unauthorized transactions
  • Gain access to internal systems through employees' mobile device
  • Bypass enterprise 2FA protections
  • Facilitate lateral movement within networks via compromised mobile credentials.

The consequences for businesses tend not to be limited by serious financial losses and reputational damage due to the exposure of sensitive customer or corporate data but escalate to operational disruption and regulatory fines.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How Does Godfather Function?

Godfather operates by impersonating legitimate applications, such as Google Protect, to gain user trust. It requests permissions to access device storage, SMS, contacts, and accessibility services. Once granted, it:

  • Runs fake scans to mimic legitimate security tools.
  • Uses on-device virtualization to create a sandbox, allowing it to hijack legitimate banking or crypto apps.
  • Intercepts user inputs and exfiltrates data to command-and-control (C&C) servers.
  • Executes commands like transferring funds or opening malicious URLs without user knowledge.

Godfather Attack Chain Live

Watch a sample of Godfather detonated in ANY.RUN’s Interactive Sandbox to analyze its execution chain and gather data for detecting the trojan and protecting your organization.

View sandbox analysis of Godfather

Godfather malware analysis in the Sandbox Godfather malware analysis in the Sandbox

In this sample, Godfather begins its execution with a dropper disguised as a legitimate-looking app, such as “Müzik İndir,” a fake music downloader. Once launched, it shows a prompt claiming a plug-in is needed. In the background, it silently installs a second-stage APK without user consent.

After installation, the malware redirects the victim to Accessibility settings. It asks the user to activate a new service named “Music Downloader.” If granted, this gives the malware full control to simulate taps, read screen content, and overlay fake elements on top of real apps.

In this specific sample, the malware does not use virtualization. However, other Godfather variants have been seen using frameworks like VirtualApp and Xposed. These allow them to sandbox and clone real banking apps, intercepting user input, screen data, and network activity in real time.

When virtualization is used, the malware launches genuine banking apps inside its controlled environment. The user sees the real interface, but everything is monitored and manipulated silently in the background. This enables seamless data theft and transaction fraud.

Godfather stores its configuration in shared preferences, including AES-encrypted and Base64-encoded C2 URLs. Campaigns typically target hundreds of apps, with many focused on Turkish financial institutions. Importantly, Godfather has been found distributed through the official Google Play Store. It often mimicked popular apps like MYT Music to bypass detection and reach a wider audience, as reported by Malwarebytes and other security vendors.

Like its predecessor, the Anubis banking trojan, Godfather is offered as malware-as-a-service, which helps explain the wide range of capabilities and variations seen across different campaigns.

Gathering Threat Intelligence on Godfather malware

Threat intelligence provides context, indicators of compromise (IOCs), and TTPs (tactics, techniques, and procedures) used by Godfather operators. It is critical in combating Godfather by:

  • Identifying IOCs: Indicators of compromise, such as C&C server IPs or malicious app signatures, help detect infections early.
  • Predicting Attack Trends: Real-time intelligence on Godfather’s evolving tactics, like virtualization, informs proactive defenses.
  • Enhancing Detection: Feeding IOCs into SIEM or EDR systems improves alert accuracy and response times.

Use ANY.RUN’s Threat Intelligence Lookup to find more Godfather public analyses in the Interactive Sandbox, watch the malware’s behavior in the network and on device, collect IOCs and IOBs.

threatName:"godfather"

Godfather samples found via TI Lookup Godfather samples recently analyzed in the Sandbox

You can also explore other malware targeting financial services users by searching the malware type “banker” in TI Lookup.

threatName:"banker"

Banking malware samples found via TI Lookup Banking trojan samples recently analyzed in the Sandbox

Regular research helps analysts follow the emerging threat patterns and build proactive protection of business assets.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Godfather is a highly adaptive and dangerous mobile malware that exploits users’ trust and weaknesses in mobile security. With the right mix of mobile protection tools, user education, and actionable threat intelligence, organizations and individuals can reduce their exposure and respond swiftly to potential infections.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Play Ransomware screenshot
Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.
Read More
SalatStealer screenshot
SalatStealer
salatstealer
SalatStealer, also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.
Read More
zgRAT screenshot
zgRAT
zgrat
zgRAT is a malware known for its ability to infect systems and exfiltrate sensitive data to command-and-control (C2) servers. It is primarily distributed through loader malware, as well as phishing emails. zgRAT employs various advanced techniques, including process injection and code obfuscation, to evade detection and maintain persistence on infected systems. The malware can also spread via USB drives and uses popular messaging platforms like Telegram and Discord for data exfiltration.
Read More
BlindEagle screenshot
BlindEagle
blindeagle
BlindEagle is a cyber threat actor primarily associated with espionage and credential theft campaigns targeting organizations in Latin America, especially Colombia. Active since at least 2018, the group relies heavily on phishing, remote access trojans (RATs), PowerShell scripts, and social engineering to infiltrate systems and maintain persistence. BlindEagle is known for continuously evolving its delivery mechanisms and malware stack to bypass detection and compromise high-value targets.
Read More
Crypto malware screenshot
Crypto malware
miner xmrig jsminer
Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More