THREAT OPS › Threat News › Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App
Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App
<p><img alt="Glitch SPY" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" height="600" src="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg" title="Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App 4" width="1200" /></p> <p><!-- wp:paragraph --></p> <p><!-- /wp:paragraph --></p> <p><!-- wp:heading --></p> <h2 class="wp-block-he
MITRE ATT&CK techniques
- Screen CaptureT1113
- JavaScriptT1059.007
- Audio CaptureT1123
- Hide ArtifactsT1564
- VulnerabilitiesT1588.006
- Clipboard DataT1115
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Data from Local SystemT1005
- Email AccountsT1586.002
- MasqueradingT1036
- Archive Collected DataT1560
- Input InjectionT1674
- Email AccountsT1585.002
- Accessibility FeaturesT1546.008
- File and Directory DiscoveryT1083
- Exfiltration Over C2 ChannelT1041
- Multi-Factor AuthenticationT1556.006
- Event Triggered ExecutionT1546
- Data Encrypted for ImpactT1486
- Input CaptureT1056
- Social MediaT1593.001
- CredentialsT1589.001
- Data DestructionT1485
- Software DiscoveryT1518
- Data from Local SystemAML.T0037
- MasqueradingAML.T0074
Indicators of compromise
- 80af5e921cf8a3052fe4483bb2eb15953590e72ed003ac61c0b9135575c32075sha256
- d439475bf09af7b474cdba2c19e136a1dd38e62b088537445ac3c8e4c2d3a8b1sha256
- https://tutaj-dompl.com/Tutajdom.apkurl
- sportypointsrewards.comdomain
- gich.etherraffleexchange.usdomain