backend.northghost.com/

domain not resolving

Tracked by C2 Tracker · Whois queried 2026-10-04T21:03:34

Registration

Registrar
—
Registered
—
Expires
—

DNS

Resolves to
13.249.231.121, 13.249.231.124, 13.249.231.127, 13.249.231.61
Nameservers
—
Status
—

Observed in malware

FamilySample SHA-256First seen
ProSpy 43e3a0b0d5e2… 2022-03-22

About ProSpy

Kotlin Android spyware (ESET's "ProSpy"; sibling strain "ToSpy") used in the "Beyond Bitter" campaign - a likely hack-for-hire operation with ties to BITTER APT (T-APT-17) targeting civil society in the Middle East, investigated jointly by Lookout and Access Now. Masquerades as secure messengers (Signal, ToTok, Botim). Task-based Worker classes exfiltrate contacts, SMS, documents, media and app backups over Retrofit endpoints under /v3/; the C2 base URL sits as a "https://host/" const-string in an obfuscated config class, with shorturl.at links used for staging in some variants.

Signing certificate

Subject CN
tucsand
Issuer CN
tucsand
Valid
2021-10-21 → 2046-10-15
Fingerprint
87d898cbd0a0d42c8c3ca0ed44ff4228ea5e5342b1cc48f7cdb65e5b4626132f

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.