youtubepremiumapp.com

domain not resolving

Tracked by C2 Tracker · Whois queried 2026-10-04T21:20:26

Registration

Registrar
Spaceship, Inc.
Registered
2026-08-06T07:12:38Z
Expires
2027-08-06T07:12:38Z

DNS

Resolves to
104.21.63.174, 172.67.148.214
Nameservers
ATHENA.NS.CLOUDFLARE.COM, MERLIN.NS.CLOUDFLARE.COM
Status
—

Observed in malware

FamilySample SHA-256First seen
Bitter 220fcfa47a11… 2022-07-06

Attributed to: Bitter (T-APT-17)

About Bitter

South-Asia-nexus APT (ETDA: T-APT-17, active since 2013) whose Android payload "Dracarys" ships inside repackaged legitimate apps (documented by Meta's Q2 2022 adversarial threat report). Dracarys components live under org.zcode.dracarys.* (services.WynkService, the accessibility service AlfredService, activities.XActivity) and abuse Accessibility Services for self-granting permissions. The C2 panel is the API_URL constant in org.zcode.dracarys.config.ApiConfig; every exfiltration channel posts to <API_URL>/v3/report/<channel> while tasking arrives over Firebase messaging. A shared ProSpy code lineage links the "Beyond Bitter" hack-for-hire campaign to this actor.

Signing certificate

Subject CN
Jarhead Alpha
Issuer CN
Jarhead Alpha
Valid
2021-02-10 → 2046-02-04
Fingerprint
d20aba6d09f06d2aa969e49c79aa78689ef2c4ab9df99a79a2323eecf74715e2

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.