APT-C-27
Malware family · 5 sample(s) · 5 indicator record(s) · 2 signing certificate(s)
About APT-C-27
Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 82.137.255.56:1740 | ip | 041b9066f42b… | 2018-07-18 |
| 82.137.255.56:1740 | ip | 2d0a56a34777… | 2018-07-16 |
| 82.137.255.56:1740 | ip | b15b5a1a1203… | 2018-07-16 |
| 82.137.255.56:1740 | ip | caf0f58ebe2f… | 2018-07-16 |
| 82.137.255.56:1740 | ip | 0713ff7bb8d9… | 2018-07-22 |
Detected samples without extractable endpoint (1)
Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| 0713ff7bb8d9… | com.sysoff.uucryptoseven.hmza | — |