version-25b53.appspot.com
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:05
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 142.250.4.153, 142.251.12.153, 142.251.175.153
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| KoSpy | 0329be10a5be… | C2 | 2025-02-07 |
| KoSpy | 75d9353c8fd8… | C2 | 2025-02-07 |
| KoSpy | cbcfcb8089ed… | C2 | 2025-02-07 |
| KoSpy | d937ea795b97… | C2 | 2025-02-07 |
Attributed to: APT37 (ScarCruft)
About KoSpy
**KoSpy** is an Android surveillance tool attributed to the North Korean actor **APT37 (ScarCruft / Reaper)**, disclosed by Lookout in 2025. Samples pose as utility apps (File Manager, Software Update, security helpers) and use a two-stage C2: the implant first pulls its live configuration and real C2 address from a Google Firebase project (hence the *.appspot.com indicators such as project-27ef0, smart-743cf and version-25b53), then beacons to the operator server. It collects SMS, call logs, location, audio recordings, screenshots, keystrokes and installed-app lists, fetching payloads on demand. Targets Korean- and English-speaking victims. APT / state-aligned.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2022-02-13 → 2052-02-13
- Fingerprint
- 2ec6f9c851aed24da396d373f91c51eaa14bde74ecd9f40bb93a804ba225d108
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.