androidupdaters.com

domain C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:03

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
ZooPark 91659d5f35a8… C2 2017-04-08
ZooPark f1ab53d9728d… C2 2018-09-11

About ZooPark

**ZooPark** is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the **Middle East** (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned.

Signing certificate

Subject CN
alal
Issuer CN
alal
Valid
2016-08-14 → 2043-12-31
Fingerprint
610be10db99f50dfa4495a83e6512aad155afb428734309b2ea2331ad9237884

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.