2.27.22.130:8443/ws
ip C2Tracked by C2 Tracker · Whois queried never
Network
- Network
- —
- CIDR
- —
- Country
- —
Contact
- Handle
- —
- Abuse
- —
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Zloy SMS RAT (provisional) | 75894da57386… | C2 | 2026-06-28 |
About Zloy SMS RAT (provisional)
Russian-targeted Android SMS-stealer and notification-interception RAT, distributed under innocuous photo/gallery app lures (e.g. "Архив фотографий"). Named for its zloy.* class namespace (zloy = Russian "evil"). Intercepts and forwards SMS/MMS and WAP-push, harvests notifications to steal one-time passcodes, and keeps itself alive with watchdog receivers, a stub sync account and a restart job. Talks to its operator over a WebSocket (ws://) C2 whose address is carried as a plaintext string resource. Family label provisional.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.