Live Android Malware Threat Feed
Public, continuously updated feed of Android malware samples analyzed by Droidwatch. sha256 hashes, package names, verdicts and severity scores — ingestible by your SIEM / MISP / OpenCTI in STIX 2.1, JSON, JSONL or CSV. No registration, no API key.
Total IOCs
2
Last 24 h
0
Generated
2026-09-13T05:58:53Z
License
CC BY 4.0
Download the feed
Latest 2 samples
| SHA-256 | Package | Verdict | Score | Seen |
|---|---|---|---|---|
| 0ad36f46238c14e5… | com.nissan.golocker | High Risk | 54 | 2026-08-16 |
| c229cd586ba61171… | com.bjmtv.ujpmp | High Risk | 63 | 2026-08-10 |
Programmatic access: all endpoints accept
?limit (max 500),
?page, ?verdict=Malicious|High Risk|Suspicious, and ?search=<pkg>.
Lookup individual hashes via GET /api/threat-feed/lookup?sha256=…. Stats via
GET /api/threat-feed/stats. See the API reference.