mobileappupdate.com/ws/agent
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-05T13:04:43
Registration
- Registrar
- Global Domain Group LLC
- Registered
- 2026-06-01T10:16:45Z
- Expires
- 2027-06-01T10:16:45Z
DNS
- Resolves to
- -
- Nameservers
- IGNACIO.NS.CLOUDFLARE.COM, TREASURE.NS.CLOUDFLARE.COM
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| GlitchSpy | 361b88ef7fea… | C2 | 2026-08-25 |
| GlitchSpy | 632d46fc6f75… | C2 | 2026-08-26 |
| GlitchSpy | 95389885777d… | C2 | 2026-08-31 |
About GlitchSpy
**GlitchSpy** is an Accessibility-abusing Android banking RAT. Using Accessibility services it performs overlay credential theft, automated UI actions and keylogging against banking and rewards apps, self-updating through benign-looking domains (mobileappupdate.com, sportypointsrewards.com) while beaconing to hard-coded operator IPs (134.255.232.216, 87.237.53.199).
Signing certificate
- Subject CN
- Kooooo Release
- Issuer CN
- Kooooo Release
- Valid
- 2026-03-30 → 2053-08-15
- Fingerprint
- 8e680f86bbca985104039dad318456f974aaff3667a3e805d23e492eaed7545a
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.