cocoacider.cc/
domainTracked by C2 Tracker Ā· Whois queried 2026-10-05T14:08:39
Registration
- Registrar
- ā
- Registered
- ā
- Expires
- ā
DNS
- Resolves to
- 172.247.99.130, 172.247.99.131, 172.247.99.132, 172.247.99.133, 172.247.99.134, 23.225.249.20, 23.225.249.21, 23.225.249.22
- Nameservers
- ā
- Status
- ā
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| RatHat | cf6fab86b34e⦠| 2026-09-09 |
About RatHat
AI-powered Android credential stealer / RAT (Zimperium, Sep 2026) posing as reward or finance apps (Tether, ReelShort lures). Serializes the live Accessibility tree to XML and queries Google Gemini to resolve on-screen targets and drive synthetic clicks. Heavy anti-analysis: a ~61 MB manifest padded with 0x9999 chunks, DEX poisoning, StringFog/StringCrypto, ZIP tampering. Config lives in a ZM26 container under assets/ (zm26_meta.json + .bt files); the C2 is the serverUrl field of server_config.json - plaintext in some builds, ZM26-encrypted in others. The primary FRP tunnel C2 is fetched at runtime by the Go agent liblocal-service.so, with libmedia_codec.so masquerading the frpc client.
Signing certificate
- Subject CN
- Debug
- Issuer CN
- Debug
- Valid
- 2026-06-28 ā 2053-11-13
- Fingerprint
- 8a9e2e175d2ea4a41bf013985c26265b0934c5ab10f575d5377db2998a6ec170
Other samples signed with this certificate? That's a lead worth checking ā but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.