logo

Bitter APT group using “Dracarys” Android Spyware

ID: 4b3989eb-7bd4-556c-884a-456ee13914f2

STIX ID: report--4b3989eb-7bd4-556c-884a-456ee13914f2

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

Cyble Research Labs identified the Bitter APT distributing Dracarys Android spyware by trojanizing legitimate messaging apps (e.g., Signal) via phishing sites; the malware abuses accessibility/device admin and requests sensitive permissions, communicates with a Firebase-based C2, and exfiltrates contacts, SMS, call logs, files, audio, and screenshots—the report includes APK hashes, malicious URLs, MITRE ATT&CK mappings, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.