Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Godfather

165
Global rank
185 infographic chevron month
Month rank
179 infographic chevron week
Week rank
0
IOCs

The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.

Trojan
Type
Unknown
Origin
1 December, 2022
First seen
14 May, 2026
Last seen

How to analyze Godfather with ANY.RUN

Type
Unknown
Origin
1 December, 2022
First seen
14 May, 2026
Last seen

IOCs

IP addresses
149.154.167.99
142.251.127.84
142.251.127.81
142.251.154.119
142.250.154.102
142.251.110.94
192.178.183.94
142.251.14.97
192.178.183.95
142.251.127.92
216.239.35.0
142.251.127.101
142.251.13.138
142.251.13.119
142.251.150.119
142.251.13.139
216.239.34.36
142.251.155.119
142.251.152.119
142.250.154.113
Hashes
e9ea8426b0adbf89b9d303a897bbe38bbbf930ffb1885dc9f41b4df9685a1cf5
89e8f90f08a0698d63d241a1db1dd20b49a4c390dd2dfaa41aad3703e55bfa4e
98f3c88e2893fb5fc322bbaf24d8c11d395c0322dce4906dce9414d8f0151ed0
c55aa588c9480ee7851d578b3306c80f5548f9ae5b3bc9afb5d126e5ef0652f0
b1c44063e9e3fd49af401ac0bc76dbb9c5b059018d43d1e29709e72f3a8a2a6f
31f7abb9248fed6be3da749d07f03592f815c5ef07ebc9afe62402cbf753ff1b
93c00a18596a49b3963102d5e33cc5dd9a1cc1ab41bf3b05244fbfa7aea366f5
dc83af4a0fe4bbb1c0663b2b5aa998f9e1ae6c18f3c7a3913214ea62c2110761
0cd3e82abd015b20fd926fc3f229686ceecfcb09acd89ab58ceda030ca3f95ff
299588f0bd00e65df421af35702a76e564c302ecc97d2b422c11d7a2465f329b
276809c60978570bfabf4a27840fe98729976339e0e3307b7c3d40ae44a9fcf4
1cffc2b3146584685cd72751d7f28aa030ab9ae2f1bc78f2c27909f8d8287b26
8c66b3cb207515328ac21bdbbda1b90a74d7cac66267352048bfd7e4e1efe627
6cd9fdd3b8fdb2df17d4d09fb17006c8eb39a3df753d04d541472a4c8e708284
8139a402ce239285716452e5668bce94bbf240b433fcfa2e154aa7e4d240445b
329ad3c7ac436f964c7a8cfcc6a74c859b51cdabd8974a65f0836410b11f2dc5
34e31d6e2cc7d11b1f6956107de3f2a7132a5da4555c692161ee1d8d0f734834
f1a61277e3f902f50ab42015d8b07218db9b7601bb0967e54a52bfdcb4fa7e81
bb6adf89f6455114a2cccb47e0575711e875b4ca9d5763c15624fea5f1f7db3c
84cb7f9b2d1653663208690d164fa1b4282e10aebe69cb5205e38182c0e297cc
Domains
staging-remoteprovisioning.sandbox.googleapis.com
accounts.google.com
www.google-analytics.com
apis.google.com
time.android.com
www.google.com
t.me
payments.google.com
google.com
play-lh.googleusercontent.com
www.googletagmanager.com
clients2.google.com
play.google.com
ssl.gstatic.com
fonts.gstatic.com
connectivitycheck.gstatic.com
www.gstatic.com
region1.google-analytics.com
content-autofill.googleapis.com
play.googleapis.com
URLs
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnivb_n4bilsty9h4qsp8ymafocvzk8gxr4c=&request_id=5c55b0f2-46d7-4d12-80dd-990163fdadb7
https://t.me/tumonokasiperake
http://clients2.google.com/time/1/current?cup2key=9:6jvtbp92njq1umro_buoceo292t07i9qoho8rjf6clw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://play.google.com/store/apps/details?id=com.lmr.lfm
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&laf=b64bin&json=standard
https://play.google.com/store/apps/details?id=com.lmr.lfm
https://fonts.gstatic.com/s/i/productlogos/avatar_anonymous/v4/web-32dp/logo_avatar_anonymous_color_1x_web_32dp.png
https://play-lh.googleusercontent.com/etayirtbvmjan2opqqnr0l76gczlbhfmegbl2nsjvchwiiyeoirk3a9ptfttpuzblea=w240-h480-rw
https://play-lh.googleusercontent.com/jyizb7tsazchgss7holbnkfmlbh-mln_11hdn8483vgxoebp7aqwnhnho4jtgj4yo53z7vvarewjbqmzzg=w48-h16-rw
https://play-lh.googleusercontent.com/jyizb7tsazchgss7holbnkfmlbh-mln_11hdn8483vgxoebp7aqwnhnho4jtgj4yo53z7vvarewjbqmzzg=s38-rw
https://play-lh.googleusercontent.com/22s8sy20xho69ircmeczqnfimghlbnlut_ia4a_vbpyzwl0feqs_22oispxqp9cy2sa=w526-h296-rw
https://play-lh.googleusercontent.com/qgze6_-elo3fn-mr1qddreoolm5tdqiq0iwaah6janrikrtykw4bnr-23ieqxybckrk=w526-h296-rw
https://play-lh.googleusercontent.com/zfmd0o-jtmmpmkdlkp5bcqubdvteek4pmgbbjnlpnyi5g5rumuyyypvqi82lozd-vw=w526-h296-rw
https://play-lh.googleusercontent.com/qkcna2kprwpndttvel6ctgbxlxflgdd0u6ridgg08gxshcmslyfam7alvjdkt7m0y2u=w526-h296-rw
https://play-lh.googleusercontent.com/ifstqoxdeluvv4t3kxkxp3otcufvwf5zqqjt7aixy4n2uavigccykxeg6ezv9fq10x1itpj1oorm=s20-rw
https://play-lh.googleusercontent.com/12usw7aflgz466ifdehktnmoaep_vhxdmkj6jebodzwcsefoc-thrx14mqe0r8kf9xczrpmqjts=s20-rw
https://play-lh.googleusercontent.com/w5dptvb8fhmkn5lbfzki_ohl3zi1rdc-aful19uk4f7np2nmjle5qqud6h0haeej977u3wh4yaq=s20-rw
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3534
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 9073
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11739
comments 0

What is Godfather malware?

Godfather is a rebranded and evolved variant of the Anubis trojan, first identified in 2022. It primarily targets Android devices, exploiting their accessibility services and employing innovative techniques such as on-device virtualization to hijack legitimate apps. This malware is designed to steal sensitive information, including banking credentials, two-factor authentication codes, and cryptocurrency wallet data.

It mimics legitimate applications and uses advanced obfuscation techniques to avoid detection. Once installed, it overlays fake login screens on top of banking and cryptocurrency apps to harvest user credentials. Godfather is actively maintained and frequently updated, making it a persistent and evolving threat.

It employs a number of vectors of system infiltration and spread:

  • Disguised as legitimate apps in third-party app stores or even Google Play (later removed)
  • Delivered via smishing (malicious SMS)
  • Embedded in phishing websites
  • Spread through social engineering campaigns
  • Sometimes distributed through cracked or modded APKs.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Godfather Victimology

Godfather primarily targets users in Europe, the U.S., and Canada, but its campaigns have also affected regions in Asia and the Middle East.

Both individual consumers and businesses, particularly those with mobile banking operations or cryptocurrency holdings, are at risk. Enterprises with employees using personal devices for corporate access (BYOD) are especially vulnerable due to the malware’s ability to compromise mobile endpoints.

What Godfather Can Do to User Device

Once installed, Godfather can severely compromise an Android device by:

  • Stealing Data: Captures SMS, contacts, login credentials, and two-factor authentication codes.
  • Screen Control: Uses Virtual Network Computing (VNC) to control the device screen remotely.
  • Keylogging: Records keystrokes to steal PINs and passwords.
  • Preventing Removal: Abuses accessibility services to block uninstallation attempts.
  • Push Notification Manipulation: Sends fake notifications to trick users into revealing sensitive information.

How Godfather Threatens Businesses and Organizations

Similar to other Android malware like Salvador Stealer and Spynote, Godfather can be used to:

  • Compromise corporate accounts and credentials
  • Steal funds or initiate unauthorized transactions
  • Gain access to internal systems through employees' mobile device
  • Bypass enterprise 2FA protections
  • Facilitate lateral movement within networks via compromised mobile credentials.

The consequences for businesses tend not to be limited by serious financial losses and reputational damage due to the exposure of sensitive customer or corporate data but escalate to operational disruption and regulatory fines.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How Does Godfather Function?

Godfather operates by impersonating legitimate applications, such as Google Protect, to gain user trust. It requests permissions to access device storage, SMS, contacts, and accessibility services. Once granted, it:

  • Runs fake scans to mimic legitimate security tools.
  • Uses on-device virtualization to create a sandbox, allowing it to hijack legitimate banking or crypto apps.
  • Intercepts user inputs and exfiltrates data to command-and-control (C&C) servers.
  • Executes commands like transferring funds or opening malicious URLs without user knowledge.

Godfather Attack Chain Live

Watch a sample of Godfather detonated in ANY.RUN’s Interactive Sandbox to analyze its execution chain and gather data for detecting the trojan and protecting your organization.

View sandbox analysis of Godfather

Godfather malware analysis in the Sandbox Godfather malware analysis in the Sandbox

In this sample, Godfather begins its execution with a dropper disguised as a legitimate-looking app, such as “Müzik İndir,” a fake music downloader. Once launched, it shows a prompt claiming a plug-in is needed. In the background, it silently installs a second-stage APK without user consent.

After installation, the malware redirects the victim to Accessibility settings. It asks the user to activate a new service named “Music Downloader.” If granted, this gives the malware full control to simulate taps, read screen content, and overlay fake elements on top of real apps.

In this specific sample, the malware does not use virtualization. However, other Godfather variants have been seen using frameworks like VirtualApp and Xposed. These allow them to sandbox and clone real banking apps, intercepting user input, screen data, and network activity in real time.

When virtualization is used, the malware launches genuine banking apps inside its controlled environment. The user sees the real interface, but everything is monitored and manipulated silently in the background. This enables seamless data theft and transaction fraud.

Godfather stores its configuration in shared preferences, including AES-encrypted and Base64-encoded C2 URLs. Campaigns typically target hundreds of apps, with many focused on Turkish financial institutions. Importantly, Godfather has been found distributed through the official Google Play Store. It often mimicked popular apps like MYT Music to bypass detection and reach a wider audience, as reported by Malwarebytes and other security vendors.

Like its predecessor, the Anubis banking trojan, Godfather is offered as malware-as-a-service, which helps explain the wide range of capabilities and variations seen across different campaigns.

Gathering Threat Intelligence on Godfather malware

Threat intelligence provides context, indicators of compromise (IOCs), and TTPs (tactics, techniques, and procedures) used by Godfather operators. It is critical in combating Godfather by:

  • Identifying IOCs: Indicators of compromise, such as C&C server IPs or malicious app signatures, help detect infections early.
  • Predicting Attack Trends: Real-time intelligence on Godfather’s evolving tactics, like virtualization, informs proactive defenses.
  • Enhancing Detection: Feeding IOCs into SIEM or EDR systems improves alert accuracy and response times.

Use ANY.RUN’s Threat Intelligence Lookup to find more Godfather public analyses in the Interactive Sandbox, watch the malware’s behavior in the network and on device, collect IOCs and IOBs.

threatName:"godfather"

Godfather samples found via TI Lookup Godfather samples recently analyzed in the Sandbox

You can also explore other malware targeting financial services users by searching the malware type “banker” in TI Lookup.

threatName:"banker"

Banking malware samples found via TI Lookup Banking trojan samples recently analyzed in the Sandbox

Regular research helps analysts follow the emerging threat patterns and build proactive protection of business assets.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Godfather is a highly adaptive and dangerous mobile malware that exploits users’ trust and weaknesses in mobile security. With the right mix of mobile protection tools, user education, and actionable threat intelligence, organizations and individuals can reduce their exposure and respond swiftly to potential infections.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More