Moneycontrol PRO
LAMF
LAMF

‘Godfather’ Android malware is back and its targeting banking apps: How it works and tips to stay safe

A new version of the Godfather Android malware uses virtualization to hijack banking apps, making it harder to detect while silently stealing credentials and executing unauthorised transactions in real time.
June 27, 2025 / 07:34 IST
Godfather malware

A dangerous new version of the Android malware known as Godfather is back and posing a significant threat to mobile banking users. This time, it uses advanced virtualisation techniques to stealthily hijack banking apps, steal login credentials, and manipulate transactions—all without raising any suspicion from the user or Android’s built-in protections.

How Godfather malware works?

The latest variant of Godfather creates isolated virtual environments directly on the infected Android device. It uses open-source tools like VirtualApp and Xposed Framework to embed a virtualisation engine within the malicious APK itself. Once a user installs the malware, it scans the device for targeted apps, which include more than 500 banking, crypto, and e-commerce apps globally.

If a target is found, Godfather launches the genuine app inside a controlled container using a technique known as StubActivity. This allows the malware to present the real app interface to the user, maintaining visual authenticity while gaining full control over the session in the background.

By intercepting app intents and using accessibility permissions, the malware records user interactions, including PINs, login credentials, and even backend communications with banking servers. To further mislead the victim, it displays fake lock screens or update messages while performing unauthorized transactions.

Why is it harder to detect?

Unlike traditional banking malware that overlays fake login screens, this version of Godfather runs the actual app inside a virtual shell. Only the host app appears in Android’s manifest, making it harder for security tools and users to detect foul play. The data exfiltration occurs seamlessly, and commands from the malware operators can be executed in real-time, enabling unauthorised transfers while the user remains unaware of any suspicious activity.

Tips to stay safe

• Download apps only from trusted sources like the Google Play Store. Avoid third-party APKs unless they come directly from verified developers.

• Enable Google Play Protect and keep it active to scan apps regularly for suspicious behaviour.

• Be cautious of apps asking for Accessibility Service permissions without a clear reason.

• Monitor battery and data usage—spikes in usage can indicate background malware activity.

• Use mobile security apps that can detect virtualisation frameworks or abnormal app behaviour.

The Godfather malware represents a new evolution in mobile threats, blending real app interfaces with deep system hooks to quietly siphon off your most sensitive data. Staying vigilant is the first line of defence.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert:

It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347