Godfather Android malware now uses virtualization to hijack banking apps
A recent iteration of the Android virus "Godfather" uses isolated virtual worlds on mobile devices to steal transactions and account information from trustworthy banking apps.
These malicious apps operate on the smartphone within a regulated virtual environment, allowing for perfect visual deception, real-time espionage, credential theft, and transaction manipulation.
The strategy is similar to the FjordPhantom Android virus, which was discovered in late 2023 and similarly employed virtualization to run SEA bank programs within containers in order to avoid detection.
Targeting more than 500 banking, cryptocurrency, and e-commerce apps globally, Godfather employs a full virtual filesystem, virtual Process ID, intent spoofing, and StubActivity.
The degree of dishonesty is extrem...


