GlitchSpy
Malware family · 4 sample(s) · 8 indicator record(s) · 2 signing certificate(s) · Active 2026-06-16 → 2026-08-31 (experimental)
About GlitchSpy
GlitchSpy is an Accessibility-abusing Android banking RAT. Using Accessibility services it performs overlay credential theft, automated UI actions and keylogging against banking and rewards apps, self-updating through benign-looking domains (mobileappupdate.com, sportypointsrewards.com) while beaconing to hard-coded operator IPs (134.255.232.216, 87.237.53.199).
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| mobileappupdate.com/ws/agent | domain | 95389885777d… | 2026-08-31 |
| mobileappupdate.com/ws/agent | domain | 361b88ef7fea… | 2026-08-25 |
| mobileappupdate.com/ws/agent | domain | 632d46fc6f75… | 2026-08-26 |
| sportypointsrewards.com | domain | 80af5e921cf8… | 2026-06-16 |
| 134.255.232.216 | ip | 95389885777d… | 2026-08-31 |
| 134.255.232.216 | ip | 361b88ef7fea… | 2026-08-25 |
| 134.255.232.216 | ip | 632d46fc6f75… | 2026-08-26 |
| 87.237.53.199 | ip | 80af5e921cf8… | 2026-06-16 |