Zloy SMS RAT (provisional)
Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s)
About Zloy SMS RAT (provisional)
Russian-targeted Android SMS-stealer and notification-interception RAT, distributed under innocuous photo/gallery app lures (e.g. “Архив фотографий”). Named for its zloy.* class namespace (zloy = Russian “evil”). Intercepts and forwards SMS/MMS and WAP-push, harvests notifications to steal one-time passcodes, and keeps itself alive with watchdog receivers, a stub sync account and a restart job. Talks to its operator over a WebSocket (ws://) C2 whose address is carried as a plaintext string resource. Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 2.27.22.130:8443/ws | ip | 75894da57386… | 2026-06-28 |