gjeikd.cdnfwersgdty.com
domainTracked by C2 Tracker · Whois queried 2026-10-04T21:20:27
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- —
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| Bitter | 6c59428863dd… | 2022-10-05 |
Attributed to: Bitter (T-APT-17)
About Bitter
South-Asia-nexus APT (ETDA: T-APT-17, active since 2013) whose Android payload "Dracarys" ships inside repackaged legitimate apps (documented by Meta's Q2 2022 adversarial threat report). Dracarys components live under org.zcode.dracarys.* (services.WynkService, the accessibility service AlfredService, activities.XActivity) and abuse Accessibility Services for self-granting permissions. The C2 panel is the API_URL constant in org.zcode.dracarys.config.ApiConfig; every exfiltration channel posts to <API_URL>/v3/report/<channel> while tasking arrives over Firebase messaging. A shared ProSpy code lineage links the "Beyond Bitter" hack-for-hire campaign to this actor.
Signing certificate
- Subject CN
- James Miller
- Issuer CN
- James Miller
- Valid
- 2021-03-02 → 2046-02-24
- Fingerprint
- 3c72ae03839502d2b459c66b49542da5e6c332207a82781fe8cd790f0cc72991
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.