75894da573866f27c3fce027…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Zloy SMS RAT (provisional). Russian-targeted Android SMS-stealer and notification-interception RAT, distributed under innocuous photo/gallery app lures (e.g. “Архив фотографий”). Named for its zloy.* class namespace (zloy = Russian “evil”). Intercepts and forwards SMS/MMS and WAP-push, harvests notifications to steal one-time passcodes, and keeps itself alive with watchdog receivers, a stub sync account and a restart job. Talks to its operator over a WebSocket (ws://) C2 whose address is carried as a plaintext string resource. Family label provisional. Indicators: ws://2.27.22.130:8443/ws.

Recovered configuration

c2_endpoint
ws://2.27.22.130:8443/ws
c2_transport
WebSocket (ws)
capabilities
SMS/MMS interception, notification (OTP) theft, watchdog persistence
lure
Архив фотографий (Russian photo-archive app)
namespace
zloy.*
package
ru.bfk5cmn2q3.g80l0szf

Identification

SHA-256
75894da573866f27c3fce027e1b3530a21dfd17e620ed49bed5c2ddf2d11a3fb
MD5
97233891c788189741a6aa2a88b3cf39

Observed

Families
Zloy SMS RAT (provisional)
First seen
2026-06-28

APK metadata

Summary

Type
Android · APK
Package
ru.bfk5cmn2q3.g80l0szf
Main activity
—
Internal version
1
Displayed version
1.0
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (2)

android.permission.ACCESS_NETWORK_STATEandroid.permission.INTERNET

Activities (6)

  • androidx.work.impl.background.NotificationTrampolineActivity
  • com.google.android.datatransport.PermissionRequestActivity
  • com.google.firebase.iid.ShareReceiverActivity
  • org.chromium.net.impl.NotificationTrampolineActivity
  • zloy.MainActivity
  • zloy.core.SmsActivity

Services (6)

  • zloy.ForegroundService
  • zloy.PushNotificationListener
  • zloy.core.RescueJobService
  • zloy.core.SmsService
  • zloy.sync.StubAuthenticatorService
  • zloy.sync.SyncService

Receivers (11)

  • androidx.lifecycle.AlarmBroadcastReceiver
  • androidx.lifecycle.PackageReplacedReceiver
  • com.google.firebase.iid.BootCompletedReceiver
  • com.unity3d.player.reflection.AlarmBroadcastReceiver
  • com.unity3d.player.reflection.BootCompletedReceiver
  • zloy.ServiceRestartReceiver
  • zloy.core.WapPushReceiver
  • zloy.core.alarm.ServiceMonitorReceiver
  • zloy.core.telephony.sms.DeliverySmsReceiver
  • zloy.core.telephony.sms.SmsReceiver
  • zloy.watchdog.WatchdogReceiver

Providers (1)

  • zloy.sync.StubContentProvider

Intent filters — actions

RESTART_SERVICESMS_DELIVEREDSMS_SENTandroid.accounts.AccountAuthenticatorandroid.content.SyncAdapterandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.LOCKED_BOOT_COMPLETEDandroid.intent.action.MIUI_BATTERY_FEATURE_CHANGEandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.RESPOND_VIA_MESSAGEandroid.intent.action.SCREEN_ONandroid.intent.action.SENDandroid.intent.action.USER_UNLOCKEDandroid.net.conn.CONNECTIVITY_CHANGEandroid.provider.Telephony.SMS_DELIVERandroid.provider.Telephony.SMS_RECEIVEDandroid.provider.Telephony.WAP_PUSH_DELIVERandroid.provider.action.DEFAULT_SMS_PACKAGE_CHANGEDandroid.service.notification.NotificationListenerServicecom.htc.intent.action.QUICKBOOT_POWERONmiui.intent.action.POWER_MODE_CHANGEDzloy.RESTART_SERVICEzloy.SERVICE_MONITORzloy.WATCHDOG_PING

Intent filters — categories

android.intent.category.DEFAULT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
2.27.22.130/ws ip 8443 ws Zloy SMS RAT (provisional) 2026-06-28

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Zloy SMS RAT (provisional)

Russian-targeted Android SMS-stealer and notification-interception RAT, distributed under innocuous photo/gallery app lures (e.g. "Архив фотографий"). Named for its zloy.* class namespace (zloy = Russian "evil"). Intercepts and forwards SMS/MMS and WAP-push, harvests notifications to steal one-time passcodes, and keeps itself alive with watchdog receivers, a stub sync account and a restart job. Talks to its operator over a WebSocket (ws://) C2 whose address is carried as a plaintext string resource. Family label provisional.