Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Aug 26, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Konfety
Konfety is an Android malware family. The provided content states that it has evolved to use ZIP manipulation and dynamic loading. It is explicitly referred to as Android malware in reporting from July 2025. No additional high-confidence details about its infection vector, specific capabilities beyond ZIP manipulation and dynamic loading, associated threat actors, targeted industries, or indicators of compromise are provided in the source content.
C2 tracking
Derp observations, rolling seven-day window
Samples
1d284a9eae9a024d72c31b3b3fbdd225b90a94b8b33838bb812b7383427d53a5 2ca21a1511f62ef46fe33805ee7e3e5c7aa2e3390684040e1f4bf30374d0c16d 6bc03e805f74d131ddf17394b586ec302db425a7679bc33a329db257375ecfe3 87c024f66d4bf0a1cf4fc8e51c282eb33f4dafddad4bde558234a267f0769fb6 bf0049067a4ac2f87cdd9ca371f75e765e6eef10e79ecc387e5cb8425e88ff73 Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.