632d46fc6f75a9b07efcb790…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
wss://mobileappupdate.com/ws/agent, 134.255.232.216.Identification
- SHA-256
- 632d46fc6f75a9b07efcb790409e4e3a0ef4ff0e99d8831c52d0d884b64eb873
- MD5
- 1859c2d821fc05d9bdf6f6a479f19088
Observed
- Families
- GlitchSpy
- First seen
- 2026-08-26
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| mobileappupdate.com/ws/agent | domain | - | wss | GlitchSpy | 2026-08-26 |
| 134.255.232.216 | ip | - | - | GlitchSpy | 2026-08-26 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- 985b768e595529e2a0007edee55046498dd067f8b4c287b1434485d9d47add07
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About GlitchSpy
**GlitchSpy** is an Accessibility-abusing Android banking RAT. Using Accessibility services it performs overlay credential theft, automated UI actions and keylogging against banking and rewards apps, self-updating through benign-looking domains (mobileappupdate.com, sportypointsrewards.com) while beaconing to hard-coded operator IPs (134.255.232.216, 87.237.53.199).