APT-C-27

Malware family · 5 sample(s) · 5 indicator record(s) · 2 signing certificate(s)

About APT-C-27

Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.

Indicators

IndicatorTypeSampleFirst seen
82.137.255.56:1740 ip 041b9066f42b… 2018-07-18
82.137.255.56:1740 ip 2d0a56a34777… 2018-07-16
82.137.255.56:1740 ip b15b5a1a1203… 2018-07-16
82.137.255.56:1740 ip caf0f58ebe2f… 2018-07-16
82.137.255.56:1740 ip 0713ff7bb8d9… 2018-07-22

Detected samples without extractable endpoint (1)

Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
0713ff7bb8d9… com.sysoff.uucryptoseven.hmza —