WebSocket SMS Stealer (provisional)

Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s) · Active 2026-10-11 (experimental)

About WebSocket SMS Stealer (provisional)

Modern Kotlin Android stealer (observed 2026) that requests SMS, call and contacts permissions and talks to its C2 over a WebSocket using the OkHttp client. Endpoints seen in captured traffic include an HTTP registration call (/api/v1/register) and a WebSocket channel (/ws) on port 8443. The implant is heavily obfuscated: strings are encrypted and the C2 configuration is stored as a custom AES-GCM container in an encrypted asset (observed name assets/.cache), so the host is not present in the DEX in any plaintext, base64, hex or single-byte-XOR form and is only resolved at runtime. Provisional bucket pending attribution.

Indicators

IndicatorTypeSampleFirst seen
144.31.167.91:8443/ws ip 6dd7c9573329… 2026-10-11