Live Android Malware Threat Feed

Public, continuously updated feed of Android malware samples analyzed by Droidwatch. sha256 hashes, package names, verdicts and severity scores — ingestible by your SIEM / MISP / OpenCTI in STIX 2.1, JSON, JSONL or CSV. No registration, no API key.

Total IOCs
3
Last 24 h
0
Generated
2026-07-30T05:21:12Z
License
CC BY 4.0

Download the feed

JSON — 500 latest JSONL — streamable CSV — spreadsheet STIX 2.1 — MISP / OpenCTI

Latest 2 samples

SHA-256 Package Verdict Score Seen
0aa75f0754ecc35a… com.com.rjblackbox.swl High Risk 58 2026-07-28
0c7490f3800562e6… dex.6e7bd5fe-ccce-410f-b7cf-cb47e9c1df8d High Risk 50 2026-07-28
Programmatic access: all endpoints accept ?limit (max 500), ?page, ?verdict=Malicious|High Risk|Suspicious, and ?search=<pkg>. Lookup individual hashes via GET /api/threat-feed/lookup?sha256=…. Stats via GET /api/threat-feed/stats. See the API reference.