ktx123.net
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:44:07
Registration
- Registrar
- Porkbun LLC
- Registered
- 2026-09-04T05:20:42Z
- Expires
- 2027-09-04T05:20:42Z
DNS
- Resolves to
- 206.82.1.14
- Nameservers
- NS1.DESEC.IO, NS2.DESEC.ORG
- Status
- -
Observed in malware
About AtlasBridge Overlay RAT (provisional)
Android overlay banker/RAT delivered inside an SVLT-XOR-v2 "vault" dropper (outer package com.system.loader.va363d031, a LaunchRouterActivity bootstrap). The dropper ships a vault-config.json that names the encrypted asset, its base64 key and the child package/hash, and a PayloadCipher that XOR-decrypts the asset (SVLT magic, embedded salt, plaintext = ct XOR salt XOR key) to a child.apk (com.atlasbridge.app). The child authenticates its C2 channel with SPAKE2 over a conscrypt TLS stack pinned by a custom x509TrustManager, carries per-device permission_profiles for overlay/accessibility abuse, and requests overlay, location and phone-state permissions. C2 recovered by a full static unpack of the vault; indicators binary-verified. Family label provisional; now tracked across 25 samples and decoded automatically by the ShellTemplateVault decoder (outer loader com.system.loader.va363d031, child com.atlasbridge.app).
Signing certificate
- Subject CN
- Nova Build 20260703113341
- Issuer CN
- Nova Build 20260703113341
- Valid
- 2026-07-03 → 2053-11-18
- Fingerprint
- af92f7d616564dabffb0679a1a38fb24d6a6c4e4a90114c6eb0834c57dd456c9
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.