6c59428863ddba27f3e3aea7…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
6c59428863ddba27f3e3aea781340ea8e05f0bca6362a7473c0595b825cf4150
MD5
e0c5d39492b2ea679a7e331ecd1a469f

Observed

Families
Bitter
First seen
2022-10-05

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
gjeikd.cdnfwersgdty.com domain — https Bitter 2022-10-05

Signing certificate

Subject CN
James Miller
Issuer CN
James Miller
Fingerprint
3c72ae03839502d2b459c66b49542da5e6c332207a82781fe8cd790f0cc72991

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Bitter

South-Asia-nexus APT (ETDA: T-APT-17, active since 2013) whose Android payload "Dracarys" ships inside repackaged legitimate apps (documented by Meta's Q2 2022 adversarial threat report). Dracarys components live under org.zcode.dracarys.* (services.WynkService, the accessibility service AlfredService, activities.XActivity) and abuse Accessibility Services for self-granting permissions. The C2 panel is the API_URL constant in org.zcode.dracarys.config.ApiConfig; every exfiltration channel posts to <API_URL>/v3/report/<channel> while tasking arrives over Firebase messaging. A shared ProSpy code lineage links the "Beyond Bitter" hack-for-hire campaign to this actor.