Bitter APT group using “Dracarys” Android Spyware
ID: 4b3989eb-7bd4-556c-884a-456ee13914f2
STIX ID: report--4b3989eb-7bd4-556c-884a-456ee13914f2
Feed Name: Cyble Blog
Threat Score
Cyble Research Labs identified the Bitter APT distributing Dracarys Android spyware by trojanizing legitimate messaging apps (e.g., Signal) via phishing sites; the malware abuses accessibility/device admin and requests sensitive permissions, communicates with a Firebase-based C2, and exfiltrates contacts, SMS, call logs, files, audio, and screenshots—the report includes APK hashes, malicious URLs, MITRE ATT&CK mappings, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
