WebSocket SMS Stealer (provisional)
Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s) · Active 2026-10-11 (experimental)
About WebSocket SMS Stealer (provisional)
Modern Kotlin Android stealer (observed 2026) that requests SMS, call and contacts permissions and talks to its C2 over a WebSocket using the OkHttp client. Endpoints seen in captured traffic include an HTTP registration call (/api/v1/register) and a WebSocket channel (/ws) on port 8443. The implant is heavily obfuscated: strings are encrypted and the C2 configuration is stored as a custom AES-GCM container in an encrypted asset (observed name assets/.cache), so the host is not present in the DEX in any plaintext, base64, hex or single-byte-XOR form and is only resolved at runtime. Provisional bucket pending attribution.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 144.31.167.91:8443/ws | ip | 6dd7c9573329… | 2026-10-11 |