3c46cc0d0b8950cac6df5666…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 3c46cc0d0b8950cac6df56665ac112b9d89823e3448a11beb57e0acd0fa1b89d
- MD5
- aec6d4933e067ade653bad7f13ff8104
Observed
- Families
- ProSpy
- First seen
- 2026-02-23
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| track-portal.co/ | domain | — | https | ProSpy | 2026-02-23 |
Signing certificate
- Subject CN
- Devid John
- Issuer CN
- Devid John
- Fingerprint
- 541ffb2cc7df82f5e87619d6e53b7d582b174d85c126ba0688cfb0d6462bf4f1
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About ProSpy
Kotlin Android spyware (ESET's "ProSpy"; sibling strain "ToSpy") used in the "Beyond Bitter" campaign - a likely hack-for-hire operation with ties to BITTER APT (T-APT-17) targeting civil society in the Middle East, investigated jointly by Lookout and Access Now. Masquerades as secure messengers (Signal, ToTok, Botim). Task-based Worker classes exfiltrate contacts, SMS, documents, media and app backups over Retrofit endpoints under /v3/; the C2 base URL sits as a "https://host/" const-string in an obfuscated config class, with shorturl.at links used for staging in some variants.