ProSpy

Malware family · 5 sample(s) · 5 indicator record(s) · 3 signing certificate(s)

About ProSpy

Kotlin Android spyware (ESET's "ProSpy"; sibling strain "ToSpy") used in the "Beyond Bitter" campaign - a likely hack-for-hire operation with ties to BITTER APT (T-APT-17) targeting civil society in the Middle East, investigated jointly by Lookout and Access Now. Masquerades as secure messengers (Signal, ToTok, Botim). Task-based Worker classes exfiltrate contacts, SMS, documents, media and app backups over Retrofit endpoints under /v3/; the C2 base URL sits as a "https://host/" const-string in an obfuscated config class, with shorturl.at links used for staging in some variants.

Indicators

IndicatorTypeSampleFirst seen
backend.northghost.com/ domain 43e3a0b0d5e2… 2022-03-22
clubline.cc/ domain 6d5feeb61c6d… 2026-02-19
relaxmode.org/ domain 9a864f104e7f… 2025-10-02
track-portal.co/ domain 0d30d0314cba… 2026-03-15
track-portal.co/ domain 3c46cc0d0b89… 2026-02-23