LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1231: GodFather

GodFather is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and other permissions to evade detection and exfiltrate sensitive data. First identified in 2020, GodFather targets nearly 500 banking applications, cryptocurrency wallets, and exchanges worldwide; however, its virtualization-based attacks have primarily focused on several Turkish financial institutions. This capability enables threat actors to steal banking credentials and other sensitive account information. [1][2]

MobileS1231MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S1231: GodFather describes [GodFather](https://attack.mitre.org/software/S1231) is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and other permissions to evade detection and exfiltrate sensitive data. First identified in 2020, [GodFather](https://attack.mitre.org/software/S1231) targets nearly 500 banking applications, cryptocurrency wallets, and exchanges worldwide; however, its virtualization-based attacks have primarily focused on several Turkish financial institutio...

Executive priority

S1231: GodFather is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S1231: GodFather by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Android), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether S1231: GodFather appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

GodFather

GodFather is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and other permissions to evade detection and exfiltrate sensitive data. First identified in 2020, GodFather targets nearly 500 banking applications, cryptocurrency wallets, and exchanges worldwide; however, its virtualization-based attacks have primarily focused on several Turkish financial institutions. This capability enables threat actors to steal banking credentials and other sensitive account information. [1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

26 rows
DomainIDNameRelationship / procedure
MobileT1624Event Triggered Execution

GodFather has executed when victims utilize their trusted banking apps, as the malware redirects the victim to using a malicious version of the banking app.[1]

MobileT1670Virtualization Solution

GodFather has used virtualization to create a separate virtual environment that mimicked legitimate banking and cryptocurrency applications.[1]

MobileT1655.001Match Legitimate Name or LocationSub-technique

GodFather has imitated Google Play Protect, a security application pre-installed on all Android devices, and its functionalities, such as scanning the device and requesting for the accessibility service.[2]

MobileT1437.001Web ProtocolsSub-technique

GodFather has leveraged WebSockets for C2.[1]

MobileT1629Impair Defenses

GodFather has intercepted API returns from banking apps that detect malicious services, and modifies the methods to return back an empty list hiding the presence of the malware and other active services.[1]

MobileT1575Native API

GodFather has hooked onto the `getEnabledAccessibilityServiceList` API to return an empty list of active services, which hides GodFather and other active services.[1]

MobileT1630Indicator Removal on Host

GodFather has requested for the `WRITE_EXTERNAL_STORAGE` permission to delete files in the device’s external storage.[2]

MobileT1636.004SMS MessagesSub-technique

GodFather has requested for the `Read_SMS` permission to access SMS messages.[2]

MobileT1429Audio Capture

GodFather has requested for the `RECORD_AUDIO` permission to record audio with the microphone.[2]

MobileT1636.003Contact ListSub-technique

GodFather has accessed the device’s contact list.[2]

MobileT1646Exfiltration Over C2 Channel

GodFather has exfiltrated sensitive information over C2.[1][2]

MobileT1629.001Prevent Application RemovalSub-technique

GodFather has abused the accessibility service to prevent the user from uninstalling itself.[2]

MobileT1617Hooking

GodFather has used the Xposed hooking framework to intercept HTTP requests and responses, capturing and exfiltrating sensitive information, such as credentials.[1]

MobileT1417.001KeyloggingSub-technique

GodFather has intercepted and recorded sensitive information from the application to include user credentials. GodFather has also leveraged a deceptive overlay that tricks users into submitting their device lock credentials which are captured.[1]

MobileT1422System Network Configuration Discovery

GodFather has accessed the device’s current cellular network information, including the phone number and the serial number.[2]

MobileT1603Scheduled Task/Job

GodFather has utilized a timer to initiate a WebSocket connection.[1]

MobileT1544Ingress Tool Transfer

GodFather has downloaded Google Play Store, Google Play services and Google Services Framework APK to a virtual folder.[1]

MobileT1453Abuse Accessibility Features

GodFather has abused the accessibility service to prevent the user from uninstalling GodFather, to exfiltrate Google Authenticator one-time passwords and to steal credentials.[2]

MobileT1516Input Injection

GodFather has abused the Accessibility Service to mimic victims’ actions and to redirect victims to its StubActivity when the victims attempt to use the original, legitimate banking application.[1]

MobileT1418Software Discovery

GodFather has gathered a list of installed applications.[1][2]

MobileT1426System Information Discovery

GodFather has the ability to gain remote control of the victim device and to gather data associated with the device, including battery level, sound settings, and device brightness.[1] GodFather has also obtained the phone's state, including network information, phone number, and serial number.[2]

MobileT1616Call Control

GodFather has requested for the `CALL_PHONE` permission to initiate phone calls.[2]

MobileT1660Phishing

GodFather has generated fake notifications to lure the victim to phishing pages.[2]

MobileT1406Obfuscated Files or Information

GodFather has obfuscated its Android manifest file with irrelevant permissions and manifest strings.[1]

MobileT1582SMS Control

GodFather has requested for the `SEND_SMS` permission to send SMS messages.[2]

MobileT1417Input Capture

GodFather has the captured information about the device's screen to include detailed tap events.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
e9566ee27d575819...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundlee9566ee27d57…
19.11.0Older bundlee9566ee27d57…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ZimperiumOrtegaPratapagiri_GodFather_Jun2025

    Ortega, F. Pratapagiri, V. (2025, June 18). Your Mobile App, Their Playground: The Dark Side of Virtualization. Retrieved July 16, 2025.

    Open source URL
  2. [2]
    MerkleScience_Godfather_April2023

    Merkle Science. (2023, April 25). The Godfather Android Malware: Threat under the lens. Retrieved July 16, 2025.

    Open source URL
  3. [3]
    mitre-attackS1231
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.