www.blackcat880.shop/

domain not resolving

Tracked by C2 Tracker · Whois queried 2026-10-05T14:08:39

Registration

Registrar
—
Registered
—
Expires
—

DNS

Resolves to
—
Nameservers
—
Status
—

Observed in malware

FamilySample SHA-256First seen
RatHat 00ba0d5aea12… 2026-04-04

About RatHat

AI-powered Android credential stealer / RAT (Zimperium, Sep 2026) posing as reward or finance apps (Tether, ReelShort lures). Serializes the live Accessibility tree to XML and queries Google Gemini to resolve on-screen targets and drive synthetic clicks. Heavy anti-analysis: a ~61 MB manifest padded with 0x9999 chunks, DEX poisoning, StringFog/StringCrypto, ZIP tampering. Config lives in a ZM26 container under assets/ (zm26_meta.json + .bt files); the C2 is the serverUrl field of server_config.json - plaintext in some builds, ZM26-encrypted in others. The primary FRP tunnel C2 is fetched at runtime by the Go agent liblocal-service.so, with libmedia_codec.so masquerading the frpc client.

Signing certificate

Subject CN
Chen Lei
Issuer CN
Chen Lei
Valid
2026-04-04 → 2053-08-20
Fingerprint
c80355bea43b333be23ac156c2cf72ddd0cc06ffd3fa4ebd1209392b199650ed

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.