Threat reportMalwareTL-2026-1195
Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader
Glitch SPY Android RAT Distributed via Fake Polish Rental (TL-2026-1195), also tracked as Glitch SPY RAT, is a high-severity malware campaign, first published 2026-07-10. It is attributed to Baron Samedit Marais with low confidence, affects Google Android OS, maps to 22 MITRE ATT&CK techniques (T1414, T1417, T1418), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 2Baron Samedit Marais
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1195
- Threat ID
- TL-2026-1195
- Also known as
- Glitch SPY RAT, Tutaj Dom Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Baron Samedit Marais, Brokewell Cyber Labs
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- realestate, financialservices, consumer, cryptocurrency
- Target regions
- poland, Europe
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Glitch SPY Android RAT Distributed via Fake Polish Rental
Malware and tooling: Brokewell, Glitch SPY, Brokewell Android Loader, Glitch SPY WebSocket C2 Panel
How Glitch SPY Android RAT Distributed via Fake Polish Rental works
A new Android RAT dubbed Glitch SPY is being distributed via a fraudulent Polish apartment-rental website (tutaj-dompl.com) impersonating a platform called "Tutaj Dom", using the Brokewell Android Loader as a dropper. Glitch SPY supports 70+ commands spanning live screen streaming, SMS/contact/call-log theft, keylogging, camera/microphone surveillance, a hidden remote-browser (WebView) module for account takeover, and a crypto-clipper targeting ETH, TRON, and Bitcoin wallet addresses.
Cyble Research and Intelligence Labs (CRIL) identified an active malware campaign distributing a new Android Remote Access Trojan named Glitch SPY through a spoofed Polish apartment-rental website, tutaj-dompl.com, which mimics a legitimate-looking rental platform branded "Tutaj Dom" (Polish for "Home Here"). Victims are lured to the site and prompted to sideload an APK (Tutajdom.apk) outside the Google Play Store. The initial payload is the Brokewell Android Loader — a dropper first identified by ThreatFabric in April 2024 and developed/sold on the Exploit cybercrime forum by an actor tracked as "Baron Samedit Marais", operating under the moniker "Brokewell Cyber Labs". The loader is notable for its ability to bypass Android 13+ 'restricted settings' protections that normally block sideloaded apps from requesting Accessibility Service permissions, and stages installation of the second-stage Glitch SPY payload.
Once installed, Glitch SPY prompts the victim to enable Android Accessibility Service, which it then abuses to auto-grant itself further dangerous permissions, perform UI automation (taps, swipes, text entry), read on-screen content, and defeat manual permission prompts. The malware maintains a persistent WebSocket connection to its command-and-control panel, exchanging structured JSON messages (hello/hello_ack handshake, heartbeat/ping keep-alive, command_result, screen_frame, sms_data, contacts_data, file_list, browser_command_result) and supports more than 70 discrete commands across surveillance, file management, remote control, and financial-fraud categories.
Surveillance capabilities include live screen streaming, screenshot capture, screen-reader text extraction, offline and live keylogging, camera streaming, microphone/audio recording, and clipboard monitoring. Data-theft commands harvest SMS messages (read and send), contacts, call logs, installed app lists, device accounts, system information, and geolocation. A full remote file manager allows listing, downloading, zipping/unzipping, renaming, and executing files, plus an AES/GCM/NoPadding file-encryption/decryption capability (FMENC1 header, .enc extension) with secure deletion (overwrite-truncate-sync-delete) of the original plaintext — though no automated mass-encryption or ransom-demand infrastructure was observed, indicating this is a targeted-extortion or evidence-destruction tool rather than a ransomware module.
A hidden, off-screen remote-browser (WebView) module lets the operator load arbitrary URLs on the victim device, toggle mobile/desktop rendering, and perform clicks, swipes, text entry, and JavaScript-driven form fills — enabling on-device account takeover using the victim's own IP address and already-authenticated web sessions, defeating IP-based and device-fingerprint fraud controls.
A dedicated crypto-clipper module (clipper_get_config/clipper_set_config/clipper_inject_clipboard) monitors the clipboard for cryptocurrency addresses and URI schemes (bitcoin:, ethereum:, erc20:, tron:, bsc:, matic:, polygon:, arbitrum:, optimism:, base:, ton:) and silently substitutes the victim's copied address with an attacker-controlled address of the matching currency family (ETH/EVM addresses starting 0x, TRON addresses starting T, Bitcoin legacy addresses starting 1 or 3, Bitcoin Bech32 addresses starting bc1q/bc1p), reporting the swap event (original address, replacement address, currency type) back to the C2.
Device-control commands allow the operator to activate/deactivate Device Administrator privileges, block biometric authentication (forcing fallback to a PIN/pattern the malware can capture), fetch/store/auto-unlock the device's lock pattern, save and auto-fill credentials, wake the screen, lock the device, hide the app icon and self-uninstall, and prevent uninstallation via Device Admin abuse.
The exposed C2 panel infrastructure includes an Agents module (searchable list of infected devices by name/ID/IP), a live Viewer for screen streaming and remote control, a Builder for compiling customized payloads (app name, package ID, launcher icon, version, notification text, decoy URL, feature toggles, Device Admin activation, Telegram alerting), a Dropper module that wraps payloads in a staging APK, a Payloads storage module, and a Cryptor module marked 'Coming soon' (planned APK repacking, re-signing, payload noise injection, and additional obfuscation) — indicating active, ongoing development of a malware-as-a-service ecosystem rather than a one-off campaign. Analysts identified a second, distinct C2 panel at gich.etherraffleexchange.us with no corresponding APK sample recovered, suggesting a broader or parallel deployment.
The campaign is Poland-focused based on the Polish-language lure and rental-platform theme, though the underlying Brokewell/Glitch SPY tooling and builder platform give the threat actor(s) the capability to reuse the same infrastructure for other regions and lure themes.
MITRE ATT&CK techniques used in TL-2026-1195
Collection
T1414 Clipboard Data; T1429 Audio Capture; T1513 Screen Capture; T1532 Archive Collected Data; T1533 Data from Local System; T1636 Protected User Data
Credential Access
T1417 Input Capture; T1453 Abuse Accessibility Features
Discovery
T1418 Software Discovery; T1420 File and Directory Discovery; T1426 System Information Discovery; T1430 Location Tracking
Command and Control
T1437 Application Layer Protocol
Impact
T1471 Data Encrypted for Impact; T1662 Data Destruction
Defense Evasion
T1516 Input Injection; T1628 Hide Artifacts; T1629 Impair Defenses; T1655 Masquerading
Persistence
T1624 Event Triggered Execution
Exfiltration
T1646 Exfiltration Over C2 Channel
Initial Access
Affected products and versions in Glitch SPY Android RAT Distributed via Fake Polish Rental
- Google — Android OS
Vulnerable versions: Android 13; Android 14; Android 15; Android 16
Remediation for Glitch SPY Android RAT Distributed via Fake Polish Rental
Immediate actions
- Block and sinkhole the identified C2/distribution domains: tutaj-dompl.com, sportypointsrewards.com, gich.etherraffleexchange.us
- Block download and execution of the known APK hashes across MDM/EDR and mobile threat defense tooling
- Alert users against sideloading APKs from rental/property-listing sites outside Google Play
- Audit and revoke Accessibility Service grants on managed Android fleets for unrecognized applications
- Enforce Google Play Protect and disable 'install unknown apps' by policy on managed devices
Workarounds
- Disable installation from unknown sources at the OS/MDM policy level
- Restrict Accessibility Service permission grants to an allowlist of vetted applications
Longer-term hardening
- Deploy mobile threat defense (MTD) with behavioral detection for Accessibility Service abuse and WebSocket-based mobile C2 beaconing
- Implement clipboard-integrity monitoring or user warnings for cryptocurrency address changes before send confirmation
- User education on rental/real-estate site sideloading lures and Android 13+ restricted-settings bypass techniques
- Monitor for reuse of the Brokewell Loader/Glitch SPY builder infrastructure against other lure themes and regions
Timeline of Glitch SPY Android RAT Distributed via Fake Polish Rental
- ThreatFabric first identifies the Brokewell Android banking trojan/loader being distributed via a fake Chrome browser-update page.
- Actor 'Baron Samedit Marais' (Brokewell Cyber Labs) advertises the Brokewell Android Loader on the Exploit cybercrime forum, marketed for its ability to bypass Android 13+ restricted-settings protections.
- Cyble Research and Intelligence Labs (CRIL) publicly discloses the Glitch SPY findings via its blog (cyble.com), releasing IOCs (domains and APK hashes) for defender consumption ahead of any vendor takedown of the identified C2/distribution infrastructure.
- Cyble publishes full technical analysis documenting Glitch SPY's 70+ command set, crypto-clipper targeting ETH/TRON/Bitcoin, hidden remote-browser module, and AES/GCM file-encryption capability.
- A second, distinct C2 panel at gich.etherraffleexchange.us is discovered with no corresponding APK sample recovered, indicating broader or parallel deployment of the platform.
- Primary Glitch SPY C2 panel at sportypointsrewards.com identified, exposing Agents, Viewer, Builder, Dropper, Payloads, and Settings modules plus a 'Coming soon' Cryptor module.
- tutaj-dompl.com confirmed serving the malicious Tutajdom.apk, chaining the Brokewell Loader dropper into the Glitch SPY second-stage payload.
- Cyble Research and Intelligence Labs (CRIL) identifies an active campaign distributing the new Glitch SPY Android RAT via the fraudulent 'Tutaj Dom' Polish rental site.
Sources cited for Glitch SPY Android RAT Distributed via Fake Polish Rental
- Glitch SPY RAT Distributed via Fake Polish App
- Brokewell: do not go broke from new banking malware!
- New 'Brokewell' Android Malware Spread Through Fake Browser Updates
- New Brokewell malware takes over Android devices, steals data
- Android Warning As Brokewell Malware Targets Banking Apps And User Data
- New 'Brokewell' Android Malware Spread Through Fake Browser Updates
- Brokewell malware targets Android banking apps
- Brokewell - AWAKE Malware Family Reference
Detection coverage for TL-2026-1195
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1195 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.