Skip to content

GodFather - Part 1 - A multistage dropper#1370

Merged
carlospolop merged 2 commits intomasterfrom
update_GodFather_-_Part_1_-_A_multistage_dropper_20250829_183210
Sep 3, 2025
Merged

GodFather - Part 1 - A multistage dropper#1370
carlospolop merged 2 commits intomasterfrom
update_GodFather_-_Part_1_-_A_multistage_dropper_20250829_183210

Conversation

@carlospolop
Copy link
Copy Markdown
Collaborator

🤖 Automated Content Update

This PR was automatically generated by the HackTricks News Bot based on a technical blog post.

📝 Source Information

🎯 Content Summary

Technical Summary: GodFather Android Banker Distribution Chain (Part 1)

Scope

First part of a deep-dive into the latest GodFather Android banker distribution chain. Focus: a multistage dropper that packs anti-reversing tricks in its APK and prepares a session-based sideload of the main payload (as also noted by Zimperium: https://shindan.io/blog/godfather-part-1-a-multistage-dropper

  • zipdetails (Archive::Zip script)
  • PKWARE ZIP specification
  • If you need, I can extend Mobile Pentesting with a compact “PackageInstaller session-based sideloading” note and detection heuristics, but it wasn’t necessary for this PR.


    This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.

    🗑️ File Cleanup

    • searchindex.js removed: This auto-generated file has been removed to prevent conflicts.

    Build master and others added 2 commits August 29, 2025 10:09
    @carlospolop
    Copy link
    Copy Markdown
    Collaborator Author

    🔗 Additional Context

    Original Blog Post: https://shindan.io/blog/godfather-part-1-a-multistage-dropper

    Content Categories: Based on the analysis, this content was categorized under "Basic Forensic Methodology -> Specific Software/File-Type Tricks -> ZIPs tricks".

    Repository Maintenance:

    • MD Files Formatting: 878 files processed

    Review Notes:

    • This content was automatically processed and may require human review for accuracy
    • Check that the placement within the repository structure is appropriate
    • Verify that all technical details are correct and up-to-date
    • All .md files have been checked for proper formatting (headers, includes, etc.)

    Bot Version: HackTricks News Bot v1.0

    @carlospolop
    Copy link
    Copy Markdown
    Collaborator Author

    merge

    @github-actions github-actions Bot force-pushed the master branch 8 times, most recently from d823bef to 93a07b2 Compare September 3, 2025 18:06
    @carlospolop carlospolop merged commit d85dbe6 into master Sep 3, 2025
    @carlospolop carlospolop deleted the update_GodFather_-_Part_1_-_A_multistage_dropper_20250829_183210 branch September 3, 2025 20:02
    github-actions Bot pushed a commit that referenced this pull request Sep 3, 2025
    …_1_-_A_multistage_dropper_20250829_183210
    
    GodFather - Part 1 - A multistage dropper
    carlospolop added a commit that referenced this pull request Sep 29, 2025
    …_1_-_A_multistage_dropper_20250829_183210
    
    GodFather - Part 1 - A multistage dropper
    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Labels

    None yet

    Projects

    None yet

    Development

    Successfully merging this pull request may close these issues.

    1 participant