logo

Uncovering Joker’s C2 Network: How Hunt’s SSL History Exposed Its Infrastructure

ID: 39b589a6-f656-52d1-9f3d-e205af782909

STIX ID: report--39b589a6-f656-52d1-9f3d-e205af782909

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report analyzes an active Joker Android malware campaign: investigators examined an APK sample (com.hdphoto.wallpaper4k.apk) and decoded staged payloads, documented POST-based C2 communications to hdphoto.uno, and used Hunt SSL-history pivots to map certificate reuse across 77 Alibaba-hosted IPs and numerous malicious domains. The write-up includes SSL certificate fingerprints, server IPs, domain lists, and file SHA-256 hashes as IOCs to aid detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.