networktopologymaps.com/user/
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:42
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| StrongPity | be9214a58046… | C2 | 2021-07-22 |
| StrongPity | a9378a546931… | C2 | 2023-01-04 |
Attributed to: StrongPity
About StrongPity
**StrongPity** (aka **Promethium** / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.
Signing certificate
- Subject CN
- Levin Levinge
- Issuer CN
- Levin Levinge
- Valid
- 2020-04-23 → 2045-04-17
- Fingerprint
- e90a429e9ba3d10985d47ad71511ffa5e296983c74267f28a88fa6a77d80ba75
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.