smart-743cf.appspot.com

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:20

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
142.250.4.153, 142.251.175.153, 64.233.170.153
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
KoSpy b0c0f38551a1… C2 2025-02-07
KoSpy da56b0416b20… C2 2025-02-07

Attributed to: APT37 (ScarCruft)

About KoSpy

**KoSpy** is an Android surveillance tool attributed to the North Korean actor **APT37 (ScarCruft / Reaper)**, disclosed by Lookout in 2025. Samples pose as utility apps (File Manager, Software Update, security helpers) and use a two-stage C2: the implant first pulls its live configuration and real C2 address from a Google Firebase project (hence the *.appspot.com indicators such as project-27ef0, smart-743cf and version-25b53), then beacons to the operator server. It collects SMS, call logs, location, audio recordings, screenshots, keystrokes and installed-app lists, fetching payloads on demand. Targets Korean- and English-speaking victims. APT / state-aligned.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2024-01-22 → 2054-01-22
Fingerprint
1be9b0f5e6f803dd9985c6971956fa6bdb6f6e48a206fa1dd677124479407aa5

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.