144.31.167.91:8443/ws

ip C2 not resolving

Tracked by C2 Tracker · Whois queried never

Network

Network
-
CIDR
-
Country
-

Contact

Handle
-
Abuse
-

Observed in malware

FamilySample SHA-256RoleFirst seen
WebSocket SMS Stealer (provisional) 6dd7c9573329… C2 2026-10-11

About WebSocket SMS Stealer (provisional)

Modern Kotlin Android stealer (observed 2026) that requests SMS, call and contacts permissions and talks to its C2 over a WebSocket using the OkHttp client. Endpoints seen in captured traffic include an HTTP registration call (/api/v1/register) and a WebSocket channel (/ws) on port 8443. The implant is heavily obfuscated: strings are encrypted and the C2 configuration is stored as a custom AES-GCM container in an encrypted asset (observed name assets/<rand>.cache), so the host is not present in the DEX in any plaintext, base64, hex or single-byte-XOR form and is only resolved at runtime. Provisional bucket pending attribution.

Signing certificate

Subject CN
APK Signer
Issuer CN
APK Signer
Valid
2019-09-03 → 2049-10-25
Fingerprint
b6da01480eefd5fbf2cd3771b8d1021ec791304bdd6c4bf41d3faabad48ee5e1

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.