{
	"id": "0e605827-81f9-4fae-92bd-b237d45f2c11",
	"created_at": "2026-04-06T00:14:14.066751Z",
	"updated_at": "2026-04-10T03:21:56.193989Z",
	"deleted_at": null,
	"sha1_hash": "72839b988fc2fbe5b32fb090549c83308a382956",
	"title": "BRATA (Malware Family)",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 45619,
	"plain_text": "BRATA (Malware Family)\r\nBy Fraunhofer FKIE\r\nArchived: 2026-04-05 16:36:31 UTC\r\napk.brata (Back to overview)\r\nBRATA\r\naka: AmexTroll, Copybara\r\nAccording to Cleafy, the victim's Android device is factory reset after the attackers siphon money from the\r\nvictim's bank account. This distracts users from the crime, while removing traces or footprints that might be of\r\ninterest to forensic analysts.\r\nReferences\r\n2022-10-12 ⋅ ThreatFabric ⋅ ThreatFabric\r\nTOAD attacks: Vishing combined with Android banking malware now targeting Italian banks\r\nBRATA Copybara Joker\r\n2022-08-04 ⋅ ThreatFabric ⋅ ThreatFabric\r\nBrata - a tale of three families\r\nAmexTroll BRATA Copybara\r\n2022-06-17 ⋅ Cleafy ⋅ Alessandro Strino, Francesco Iubatti\r\nBRATA is evolving into an Advanced Persistent Threat\r\nBRATA\r\n2022-01-24 ⋅ Cleafy ⋅ Cleafy\r\nHow BRATA is monitoring your bank account\r\nBRATA\r\n2021-12-03 ⋅ Cleafy ⋅ Cleafy\r\nMobile banking fraud: BRATA strikes again\r\nBRATA\r\nhttps://malpedia.caad.fkie.fraunhofer.de/details/apk.brata\r\nPage 1 of 2\n\n2021-02-22 ⋅ AdvIntel ⋅ Beatriz Pimenta Klein\r\nEconomic Growth, Digital Inclusion, \u0026 Specialized Crime: Financial Cyber Fraud in LATAM\r\nBRATA Mekotio Metamorfo Ploutus ATM VictoryGate\r\n2019-08-29 ⋅ Kaspersky Labs ⋅ GReAT\r\nFully equipped Spying Android RAT from Brazil: BRATA\r\nBRATA\r\nThere is no Yara-Signature yet.\r\nSource: https://malpedia.caad.fkie.fraunhofer.de/details/apk.brata\r\nhttps://malpedia.caad.fkie.fraunhofer.de/details/apk.brata\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://malpedia.caad.fkie.fraunhofer.de/details/apk.brata"
	],
	"report_names": [
		"apk.brata"
	],
	"threat_actors": [],
	"ts_created_at": 1775434454,
	"ts_updated_at": 1775791316,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/72839b988fc2fbe5b32fb090549c83308a382956.pdf",
		"text": "https://archive.orkl.eu/72839b988fc2fbe5b32fb090549c83308a382956.txt",
		"img": "https://archive.orkl.eu/72839b988fc2fbe5b32fb090549c83308a382956.jpg"
	}
}