220fcfa47a11e7e3f179a962…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 220fcfa47a11e7e3f179a96258a5bb69914c17e8ca7d0fdce44d13f1f3229548
- MD5
- 07532dea34c87ea2c91d2e035ed5dc87
Observed
- Families
- Bitter
- First seen
- 2022-07-06
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| youtubepremiumapp.com | domain | — | https | Bitter | 2022-07-06 |
Signing certificate
- Subject CN
- Jarhead Alpha
- Issuer CN
- Jarhead Alpha
- Fingerprint
- d20aba6d09f06d2aa969e49c79aa78689ef2c4ab9df99a79a2323eecf74715e2
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Bitter
South-Asia-nexus APT (ETDA: T-APT-17, active since 2013) whose Android payload "Dracarys" ships inside repackaged legitimate apps (documented by Meta's Q2 2022 adversarial threat report). Dracarys components live under org.zcode.dracarys.* (services.WynkService, the accessibility service AlfredService, activities.XActivity) and abuse Accessibility Services for self-granting permissions. The C2 panel is the API_URL constant in org.zcode.dracarys.config.ApiConfig; every exfiltration channel posts to <API_URL>/v3/report/<channel> while tasking arrives over Firebase messaging. A shared ProSpy code lineage links the "Beyond Bitter" hack-for-hire campaign to this actor.