Skip to content

Konfety

Konfety is an Android malware family.

Profile source: Mallory opens in a new tab

Konfety

Family profile

Konfety is an Android malware family. The provided content states that it has evolved to use ZIP manipulation and dynamic loading. It is explicitly referred to as Android malware in reporting from July 2025. No additional high-confidence details about its infection vector, specific capabilities beyond ZIP manipulation and dynamic loading, associated threat actors, targeted industries, or indicators of compromise are provided in the source content.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Aug 26, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.