GlitchSpy

Malware family · 4 sample(s) · 8 indicator record(s) · 2 signing certificate(s) · Active 2026-06-16 → 2026-08-31 (experimental)

About GlitchSpy

GlitchSpy is an Accessibility-abusing Android banking RAT. Using Accessibility services it performs overlay credential theft, automated UI actions and keylogging against banking and rewards apps, self-updating through benign-looking domains (mobileappupdate.com, sportypointsrewards.com) while beaconing to hard-coded operator IPs (134.255.232.216, 87.237.53.199).

Indicators

IndicatorTypeSampleFirst seen
mobileappupdate.com/ws/agent domain 95389885777d… 2026-08-31
mobileappupdate.com/ws/agent domain 361b88ef7fea… 2026-08-25
mobileappupdate.com/ws/agent domain 632d46fc6f75… 2026-08-26
sportypointsrewards.com domain 80af5e921cf8… 2026-06-16
134.255.232.216 ip 95389885777d… 2026-08-31
134.255.232.216 ip 361b88ef7fea… 2026-08-25
134.255.232.216 ip 632d46fc6f75… 2026-08-26
87.237.53.199 ip 80af5e921cf8… 2026-06-16