Zloy SMS RAT (provisional)

Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s)

About Zloy SMS RAT (provisional)

Russian-targeted Android SMS-stealer and notification-interception RAT, distributed under innocuous photo/gallery app lures (e.g. “Архив фотографий”). Named for its zloy.* class namespace (zloy = Russian “evil”). Intercepts and forwards SMS/MMS and WAP-push, harvests notifications to steal one-time passcodes, and keeps itself alive with watchdog receivers, a stub sync account and a restart job. Talks to its operator over a WebSocket (ws://) C2 whose address is carried as a plaintext string resource. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
2.27.22.130:8443/ws ip 75894da57386… 2026-06-28