Live Android Malware Threat Feed

Public, continuously updated feed of Android malware samples analyzed by Droidwatch. sha256 hashes, package names, verdicts and severity scores — ingestible by your SIEM / MISP / OpenCTI in STIX 2.1, JSON, JSONL or CSV. No registration, no API key.

Total IOCs
2
Last 24 h
0
Generated
2026-09-13T05:58:53Z
License
CC BY 4.0

Download the feed

JSON — 500 latest JSONL — streamable CSV — spreadsheet STIX 2.1 — MISP / OpenCTI

Latest 2 samples

SHA-256 Package Verdict Score Seen
0ad36f46238c14e5… com.nissan.golocker High Risk 54 2026-08-16
c229cd586ba61171… com.bjmtv.ujpmp High Risk 63 2026-08-10
Programmatic access: all endpoints accept ?limit (max 500), ?page, ?verdict=Malicious|High Risk|Suspicious, and ?search=<pkg>. Lookup individual hashes via GET /api/threat-feed/lookup?sha256=…. Stats via GET /api/threat-feed/stats. See the API reference.