ProSpy
Malware family · 5 sample(s) · 5 indicator record(s) · 3 signing certificate(s)
About ProSpy
Kotlin Android spyware (ESET's "ProSpy"; sibling strain "ToSpy") used in the "Beyond Bitter" campaign - a likely hack-for-hire operation with ties to BITTER APT (T-APT-17) targeting civil society in the Middle East, investigated jointly by Lookout and Access Now. Masquerades as secure messengers (Signal, ToTok, Botim). Task-based Worker classes exfiltrate contacts, SMS, documents, media and app backups over Retrofit endpoints under /v3/; the C2 base URL sits as a "https://host/" const-string in an obfuscated config class, with shorturl.at links used for staging in some variants.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| backend.northghost.com/ | domain | 43e3a0b0d5e2… | 2022-03-22 |
| clubline.cc/ | domain | 6d5feeb61c6d… | 2026-02-19 |
| relaxmode.org/ | domain | 9a864f104e7f… | 2025-10-02 |
| track-portal.co/ | domain | 0d30d0314cba… | 2026-03-15 |
| track-portal.co/ | domain | 3c46cc0d0b89… | 2026-02-23 |