A new, highly sophisticated variant of the Android malware “Godfather” has emerged, introducing innovative virtualization tactics to steal banking and financial data. According to security researchers, the threat uses virtual environments within the device to mimic legitimate banking and e-commerce applications, deceiving the user and bypassing Android’s security mechanisms.

The malware executes its attacks from within a fully controlled virtual environment, allowing for real-time monitoring, credential theft , and transaction modification – all without arousing suspicion. The user experience remains unchanged, as they observe the normal application environment, while a completely different process runs in the background.
See also: BlueNoroff distributes MacOS malware via deepfake videos in Zoom meetings
The technique is reminiscent of the methods of the “FjordPhantom” malware, which was detected in late 2023 and also used virtualization to run SEA bank apps in containers. However, Godfather is proving to be much more ambitious, targeting over 500 applications worldwide – from banks and cryptocurrency exchangesto e-commerce platforms.
Its infrastructure is based on virtual filesystem, virtual Process ID, intent spoofing and StubActivity . As Zimperium , which analyzed the new version of Godfather, explains , the level of deception is so high that Android does not recognize the activity as harmful.
Godfather is distributed as an APK app that includes a built-in virtualization framework, leveraging popular open-source tools such as the VirtualApp engine and Xposed. After installation, it detects target applications, “ports” them to a virtual environment, and uses a StubActivity to launch them inside the host container.
StubActivity acts as a shell or proxy that allows activities to be launched and executed by virtualized applications. It does not have its own UI; instead, it acts as an intermediary, tricking Android into thinking that a normal application is running. In reality, however, this activity transfers control to the malicious application.
See also: Secure Boot flaw allows bootkit malware installation
When an unsuspecting user opens a banking app, the Godfather malware – exploiting the accessibility permission – redirects the process to the StubActivity within the host app. There, a virtual version of the application is launched inside a container, remaining invisible to the system.
Although the user sees the authentic interface, their actions – from entering login details to completing transactions – are recorded in real time. With the help of the Xposed, mentioned above, Godfather records account credentials, passwords, PINs.
In fact, to extract even more information, the malware employs social engineering techniques: it displays fake lock screens at critical moments, tricking the user into re-typing sensitive data. Once it has collected and extracted all this data, it waits for commands from the operators to unlock the device, perform UI navigation, open applications, and trigger payments/transfers from the real banking application.
During this process, the user sees a fake “update” screen or a black screen and thus does not understand the malicious activity.

A constantly evolving threat
Godfather was first spotted in March 2021 by ThreatFabric and has since shown significant technological evolution. The latest version far surpasses the December 2022 sample analyzed by Group-IB , which targeted 400 applications in 16 countries.
The new campaign, as spotted by Zimperium, is currently focused on 12 banking apps in Turkey. However, the malware supports attacks on more than 500 apps worldwide – including banks, cryptocurrency exchanges and e-commerce platforms. Each Godfather variant can trigger different “target packages”, depending on the region or malicious service provider.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: DanaBot Malware server vulnerability reveals hacker credentials
How to protect yourself
To avoid such attacks, experts recommend downloading apps only from Google Play and other trusted app stores. However, some malicious apps manage to get through there too. For this reason, you should always confirm the authenticity of an app before installing it. This can be done reviews user. You can also visit the official website of a service and find the link there to download the app from the app store.
Avoid APKs from unknown sources and keep Play Protect enabled.
It's also important to check the permissions that apps request, even if they're on Google Play. If an app asks for access to personal information that doesn't seem necessary for it to function, it's best to avoid installing it.
It is also essential to use reliable security software and regularly update your operating system and applications. Finally, you should avoid sharing your personal information with untrusted sources.
Source: www.bleepingcomputer.com
