BladeHawk

Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)

About BladeHawk

Android spyware family identified by its distinctive package dat.a8andoserverx with a persistent MainService. The C2 host and port sit as plain const-strings in an inner thread class (MainService$1), handed directly to InetAddress.getByName() and Integer.parseInt().

Indicators

IndicatorTypeSampleFirst seen
adam9.ddns.net:4000 domain d3033e7305b2… 2021-10-07
alex00.ddns.net:4000 domain 2a4cf22220b9… 2021-09-10