6dd7c9573329ba8ae5389dd8…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

WebSocket SMS Stealer (provisional). Modern Kotlin Android stealer (observed 2026) that requests SMS, call and contacts permissions and talks to its C2 over a WebSocket using the OkHttp client. Endpoints seen in captured traffic include an HTTP registration call (/api/v1/register) and a WebSocket channel (/ws) on port 8443. The implant is heavily obfuscated: strings are encrypted and the C2 configuration is stored as a custom AES-GCM container in an encrypted asset (observed name assets/.cache), so the host is not present in the DEX in any plaintext, base64, hex or single-byte-XOR form and is only resolved at runtime. Provisional bucket pending attribution. Indicators: wss://144.31.167.91:8443/ws.

Recovered configuration

config_storage
custom AES-GCM container in assets/ly4s4kq1rq.cache (strings also encrypted)
endpoints
/api/v1/register (HTTP 200), /ws (WebSocket 101)
package
ndxllm.w6ofct3bk.txib06
transport
WebSocket over OkHttp (TLS :8443)

Identification

SHA-256
6dd7c9573329ba8ae5389dd89e569d41d28db9a50e8172ad2f087c72370ad83a
MD5
5798712fd54329c4a9f085b9a1f98a7a

Observed

Families
WebSocket SMS Stealer (provisional)
First seen
2026-10-11

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
144.31.167.91/ws ip 8443 wss WebSocket SMS Stealer (provisional) 2026-10-11

Signing certificate

Subject CN
APK Signer
Issuer CN
APK Signer
Fingerprint
b6da01480eefd5fbf2cd3771b8d1021ec791304bdd6c4bf41d3faabad48ee5e1

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About WebSocket SMS Stealer (provisional)

Modern Kotlin Android stealer (observed 2026) that requests SMS, call and contacts permissions and talks to its C2 over a WebSocket using the OkHttp client. Endpoints seen in captured traffic include an HTTP registration call (/api/v1/register) and a WebSocket channel (/ws) on port 8443. The implant is heavily obfuscated: strings are encrypted and the C2 configuration is stored as a custom AES-GCM container in an encrypted asset (observed name assets/<rand>.cache), so the host is not present in the DEX in any plaintext, base64, hex or single-byte-XOR form and is only resolved at runtime. Provisional bucket pending attribution.