Godfather Android Malware - What it is, warning signs, and how to remove and prevent it

Godfather Android Malware

What it is

Godfather is an Android banking trojan that overlays fake login screens on top of real banking and crypto apps to steal credentials, SMS codes, and seed phrases. It can also read notifications and intercept 2FA to drain accounts. Technical details and removal tips: see our Godfather on Android - overview for defenders.

What you may notice

  • Banking or wallet apps show odd pop-ups or ask for extra permissions

  • Unexpected SMS verification prompts or missing 2FA texts

  • New accessibility service enabled that you didn’t turn on

  • Battery and data usage spike without a clear reason

How it gets in

  • Fake app updates and clones in third-party stores

  • Malicious links in SMS, email, or messaging apps

  • “Security” or “system” apps pushing for Accessibility or Notification access

Remove it now - quick steps

  1. Disconnect from the internet - turn on airplane mode.

  2. Open Settings → Apps and uninstall suspicious or newly added apps.

  3. In Settings → Security → Device admin apps and Accessibility, disable unknown entries.

  4. Install and run a reputable mobile anti-malware, then reboot and scan again.

  5. From a clean device, change passwords for banking, email, and crypto - move funds to new wallets with fresh seed phrases.

Prevent it

  • Install apps only from Google Play - avoid third-party stores and APKs.

  • Be cautious with links - especially those prompting urgent “bank updates.”

  • Review permissions regularly - revoke Accessibility and Notification access for apps that shouldn’t need it.

  • Turn on Play Protect, keep Android and apps updated, and use MFA with an authenticator app or security key.

    Glossary (A–Z)

    All A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
      • Related Articles

      • Mobile Malware

        What it is Mobile malware is malicious software that targets phones and tablets. It can steal messages and passwords, spy through permissions, hijack your browser, or lock files for ransom. Infections usually arrive through shady apps, smishing ...
      • Mobile Code

        What it is Mobile code is code that arrives with a page, message, or app and runs automatically on your device. Think scripts, macros, plug-ins, and mini apps that add features like forms, animations, or in-app widgets. When misused, the same ...
      • Data Execution Prevention

        What it is Data Execution Prevention (DEP) is a Windows safety net that stops code from running in places it shouldn’t—like the stack or heap. If malware tries to execute from those memory areas, Windows blocks it and shuts the app down instead of ...
      • LokiBot (Loki Password Stealer)

        LokiBot (Loki Password Stealer) What it is LokiBot is a credential-stealing trojan that targets Windows and Android. It grabs passwords, cookies, and wallet data, can take screenshots, and sometimes opens a backdoor for more malware. Technical ...
      • Malware

        What it is Malware is any software made to harm your device or data. It can steal passwords, lock your files, spy on activity, or hijack your browser. For a quick primer and examples, see our malware explainer. How it spreads Phishing emails and fake ...