/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Reports: an Android malware called Godfather is using overlaid login screens to get users' credentials on 400+ banking apps and crypto exchanges in 16 countries

An Android banking malware named ‘Godfather’ has been targeting users in 16 countries, attempting to steal account credentials … Source: Cyble .

BleepingComputer Bill Toulas

Context & Ripple Effects

Godfather extends an established Android banking-malware pattern from narrowly targeted impersonation to broad app coverage. Two months earlier, Drinik impersonated India’s tax app to target 18 banks, while Gustuff had already combined credential phishing with automated bank transactions across banks and virtual-currency apps.

The reported overlay technique matters because it targets the login moment across both banking and crypto services, rather than relying on a single fraudulent app identity.

First-order effects

  • Users of the 400-plus targeted banking apps and crypto exchanges face credential theft through counterfeit login screens presented over legitimate Android apps.
  • Banks and crypto exchanges in the 16 affected countries must treat Android login credentials as exposed through an interface-level phishing route, not solely through fake standalone apps.

Second-order effects

  • The breadth of Godfather’s target list raises the value of authentication and transaction checks that do not depend only on a password entered in an Android app.
  • Android malware operators have an incentive to favor reusable overlay campaigns over country-specific lures such as Drinik’s tax-app disguise, expanding the set of financial services that must defend against the same technique.

Third-order effects

  • The pattern points to Android financial fraud becoming more platform-oriented: malware families can reuse credential-harvesting methods across banks and crypto services while changing the branded screen shown to each victim.
  • As credential phishing and transaction automation appear in the same Android threat lineage, illustrated by Gustuff’s banking and virtual-currency targeting, payment risk increasingly hinges on whether providers can distinguish a legitimate session from a compromised device interaction.

The trend: Android financial malware is shifting toward reusable credential-harvesting layers that can be applied across many branded banking and crypto apps.

Discussion

  • @virusbtn @virusbtn on x
    Cyble researchers identified several GodFather Android samples masquerading as the MYT Müzik app to target Turkish users. GodFather is a notorious Android banking trojan known for targeting banking users, mostly in European countries. https://blog.cyble.com/... https://twitter.co…
  • @ourielohayon @ourielohayon on x
    If you use a crypto wallet with seed phrases or private keys or passwords this is *very* bad. https://twitter.com/...
  • @sentientsixp @sentientsixp on x
    Behind every successful fortune there is a crime. “the trojan is configured to check the system language, and if it's set to Russian, Azerbaijani, Armenian, Belarusian, Kazakh, Kyrgyz, Moldovan, Uzbek, or Tajik, it stops its operation” https://twitter.com/...