2.27.22.130:8443/ws

ip C2 not resolving

Tracked by C2 Tracker · Whois queried never

Network

Network
—
CIDR
—
Country
—

Contact

Handle
—
Abuse
—

Observed in malware

FamilySample SHA-256RoleFirst seen
Zloy SMS RAT (provisional) 75894da57386… C2 2026-06-28

About Zloy SMS RAT (provisional)

Russian-targeted Android SMS-stealer and notification-interception RAT, distributed under innocuous photo/gallery app lures (e.g. "Архив фотографий"). Named for its zloy.* class namespace (zloy = Russian "evil"). Intercepts and forwards SMS/MMS and WAP-push, harvests notifications to steal one-time passcodes, and keeps itself alive with watchdog receivers, a stub sync account and a restart job. Talks to its operator over a WebSocket (ws://) C2 whose address is carried as a plaintext string resource. Family label provisional.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.