backend.northghost.com/
domainTracked by C2 Tracker · Whois queried 2026-10-04T21:03:34
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- 13.249.231.121, 13.249.231.124, 13.249.231.127, 13.249.231.61
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| ProSpy | 43e3a0b0d5e2… | 2022-03-22 |
About ProSpy
Kotlin Android spyware (ESET's "ProSpy"; sibling strain "ToSpy") used in the "Beyond Bitter" campaign - a likely hack-for-hire operation with ties to BITTER APT (T-APT-17) targeting civil society in the Middle East, investigated jointly by Lookout and Access Now. Masquerades as secure messengers (Signal, ToTok, Botim). Task-based Worker classes exfiltrate contacts, SMS, documents, media and app backups over Retrofit endpoints under /v3/; the C2 base URL sits as a "https://host/" const-string in an obfuscated config class, with shorturl.at links used for staging in some variants.
Signing certificate
- Subject CN
- tucsand
- Issuer CN
- tucsand
- Valid
- 2021-10-21 → 2046-10-15
- Fingerprint
- 87d898cbd0a0d42c8c3ca0ed44ff4228ea5e5342b1cc48f7cdb65e5b4626132f
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.