0d30d0314cbac92e7399a043…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
0d30d0314cbac92e7399a043582b6558b86ba72313fd222db4d5cf8ca18f7cbb
MD5
3279b467dcc9d779d86c3776c88b1748

Observed

Families
ProSpy
First seen
2026-03-15

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
track-portal.co/ domain — https ProSpy 2026-03-15

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About ProSpy

Kotlin Android spyware (ESET's "ProSpy"; sibling strain "ToSpy") used in the "Beyond Bitter" campaign - a likely hack-for-hire operation with ties to BITTER APT (T-APT-17) targeting civil society in the Middle East, investigated jointly by Lookout and Access Now. Masquerades as secure messengers (Signal, ToTok, Botim). Task-based Worker classes exfiltrate contacts, SMS, documents, media and app backups over Retrofit endpoints under /v3/; the C2 base URL sits as a "https://host/" const-string in an obfuscated config class, with shorturl.at links used for staging in some variants.