8968d6ed113bd90414f5c8dc…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

NFC Relay (provisional). Android NFC-relay fraud malware. Running on a victim’s phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / “NGate”-style technique). Observed C2 infrastructure includes dashboardcloud.app / api.dashboardcloud.app, dashboard.gripe and 178.236.243.8. Family label provisional. Indicators: wss://dashboard.gripe/ws-relay, https://dashboardcloud.app, https://api.dashboardcloud.app/api/status.

Recovered configuration

backend_urls
https://dashboardcloud.app, https://api.dashboardcloud.app/api/status
build_id
2363b211bfb1
config_id
e69ea27c
relay_c2
wss://dashboard.gripe/ws-relay

Source: string-reversed URLs in dex (bs config, UtilZ0Y480.decode = reverse)

Identification

SHA-256
8968d6ed113bd90414f5c8dc76e628867388ac0d94eb76399c188a3994f5b50e
MD5
8748b861416547f7d50b8046eec6305a

Observed

Families
NFC Relay (provisional)
First seen
2026-10-08

C2 configuration (3)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.dashboardcloud.app/api/status domain - https NFC Relay (provisional) 2026-10-08
dashboard.gripe/ws-relay domain - wss NFC Relay (provisional) 2026-10-08
dashboardcloud.app domain - https NFC Relay (provisional) 2026-10-08

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
b3840ad71ff86c793c23da76c33c44f67d35099917b816895dacc8a614ddd116

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About NFC Relay (provisional)

Android NFC-relay fraud malware. Running on a victim's phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / "NGate"-style technique). Observed C2 infrastructure includes dashboardcloud.app / api.dashboardcloud.app, dashboard.gripe and 178.236.243.8. Family label provisional.