361b88ef7fea0f7d15fbef41…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

GlitchSpy. GlitchSpy is an Accessibility-abusing Android banking RAT. Using Accessibility services it performs overlay credential theft, automated UI actions and keylogging against banking and rewards apps, self-updating through benign-looking domains (mobileappupdate.com, sportypointsrewards.com) while beaconing to hard-coded operator IPs (134.255.232.216, 87.237.53.199). Indicators: wss://mobileappupdate.com/ws/agent, 134.255.232.216.

Identification

SHA-256
361b88ef7fea0f7d15fbef411b65141609164a2751ce44a8a1785f9f22f4892f
MD5
1f238a40afbe774d4a53c591c6c63d2b

Observed

Families
GlitchSpy
First seen
2026-08-25

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
mobileappupdate.com/ws/agent domain - wss GlitchSpy 2026-08-25
134.255.232.216 ip - - GlitchSpy 2026-08-25

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
985b768e595529e2a0007edee55046498dd067f8b4c287b1434485d9d47add07

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About GlitchSpy

**GlitchSpy** is an Accessibility-abusing Android banking RAT. Using Accessibility services it performs overlay credential theft, automated UI actions and keylogging against banking and rewards apps, self-updating through benign-looking domains (mobileappupdate.com, sportypointsrewards.com) while beaconing to hard-coded operator IPs (134.255.232.216, 87.237.53.199).