# Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader

> A new Android RAT dubbed Glitch SPY is being distributed via a fraudulent Polish apartment-rental website (tutaj-dompl.com) impersonating a platform called "Tutaj Dom", using the Brokewell Android Loader as a dropper. Glitch SPY supports 70+ commands spanning live screen streaming, SMS/contact/call-log theft, keylogging, camera/microphone surveillance, a hidden remote-browser (WebView) module for account takeover, and a crypto-clipper targeting ETH, TRON, and Bitcoin wallet addresses.

- **Published:** 2026-07-10T00:00:00Z
- **Last reviewed:** 2026-07-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1195
- **ID:** TL-2026-1195
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Baron Samedit Marais
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Cyble Research and Intelligence Labs (CRIL) identified an active malware campaign distributing a new Android Remote Access Trojan named Glitch SPY through a spoofed Polish apartment-rental website, tutaj-dompl.com, which mimics a legitimate-looking rental platform branded "Tutaj Dom" (Polish for "Home Here"). Victims are lured to the site and prompted to sideload an APK (Tutajdom.apk) outside the Google Play Store. The initial payload is the Brokewell Android Loader — a dropper first identified by ThreatFabric in April 2024 and developed/sold on the Exploit cybercrime forum by an actor tracked as "Baron Samedit Marais", operating under the moniker "Brokewell Cyber Labs". The loader is notable for its ability to bypass Android 13+ 'restricted settings' protections that normally block sideloaded apps from requesting Accessibility Service permissions, and stages installation of the second-stage Glitch SPY payload.

Once installed, Glitch SPY prompts the victim to enable Android Accessibility Service, which it then abuses to auto-grant itself further dangerous permissions, perform UI automation (taps, swipes, text entry), read on-screen content, and defeat manual permission prompts. The malware maintains a persistent WebSocket connection to its command-and-control panel, exchanging structured JSON messages (hello/hello_ack handshake, heartbeat/ping keep-alive, command_result, screen_frame, sms_data, contacts_data, file_list, browser_command_result) and supports more than 70 discrete commands across surveillance, file management, remote control, and financial-fraud categories.

Surveillance capabilities include live screen streaming, screenshot capture, screen-reader text extraction, offline and live keylogging, camera streaming, microphone/audio recording, and clipboard monitoring. Data-theft commands harvest SMS messages (read and send), contacts, call logs, installed app lists, device accounts, system information, and geolocation. A full remote file manager allows listing, downloading, zipping/unzipping, renaming, and executing files, plus an AES/GCM/NoPadding file-encryption/decryption capability (FMENC1 header, .enc extension) with secure deletion (overwrite-truncate-sync-delete) of the original plaintext — though no automated mass-encryption or ransom-demand infrastructure was observed, indicating this is a targeted-extortion or evidence-destruction tool rather than a ransomware module.

A hidden, off-screen remote-browser (WebView) module lets the operator load arbitrary URLs on the victim device, toggle mobile/desktop rendering, and perform clicks, swipes, text entry, and JavaScript-driven form fills — enabling on-device account takeover using the victim's own IP address and already-authenticated web sessions, defeating IP-based and device-fingerprint fraud controls.

A dedicated crypto-clipper module (clipper_get_config/clipper_set_config/clipper_inject_clipboard) monitors the clipboard for cryptocurrency addresses and URI schemes (bitcoin:, ethereum:, erc20:, tron:, bsc:, matic:, polygon:, arbitrum:, optimism:, base:, ton:) and silently substitutes the victim's copied address with an attacker-controlled address of the matching currency family (ETH/EVM addresses starting 0x, TRON addresses starting T, Bitcoin legacy addresses starting 1 or 3, Bitcoin Bech32 addresses starting bc1q/bc1p), reporting the swap event (original address, replacement address, currency type) back to the C2.

Device-control commands allow the operator to activate/deactivate Device Administrator privileges, block biometric authentication (forcing fallback to a PIN/pattern the malware can capture), fetch/store/auto-unlock the device's lock pattern, save and auto-fill credentials, wake the screen, lock the device, hide the app icon and self-uninstall, and prevent uninstallation via Device Admin abuse.

The exposed C2 panel infrastructure includes an Agents module (searchable list of infected devices by name/ID/IP), a live Viewer for screen streaming and remote control, a Builder for compiling customized payloads (app name, package ID, launcher icon, version, notification text, decoy URL, feature toggles, Device Admin activation, Telegram alerting), a Dropper module that wraps payloads in a staging APK, a Payloads storage module, and a Cryptor module marked 'Coming soon' (planned APK repacking, re-signing, payload noise injection, and additional obfuscation) — indicating active, ongoing development of a malware-as-a-service ecosystem rather than a one-off campaign. Analysts identified a second, distinct C2 panel at gich.etherraffleexchange.us with no corresponding APK sample recovered, suggesting a broader or parallel deployment.

The campaign is Poland-focused based on the Polish-language lure and rental-platform theme, though the underlying Brokewell/Glitch SPY tooling and builder platform give the threat actor(s) the capability to reuse the same infrastructure for other regions and lure themes.

## MITRE ATT&CK

- T1660 Phishing
- T1624 Event Triggered Execution
- T1629 Impair Defenses
- T1628 Hide Artifacts
- T1655 Masquerading
- T1516 Input Injection
- T1453 Abuse Accessibility Features
- T1417 Input Capture
- T1418 Software Discovery
- T1420 File and Directory Discovery
- T1430 Location Tracking
- T1426 System Information Discovery
- T1532 Archive Collected Data
- T1513 Screen Capture
- T1429 Audio Capture
- T1414 Clipboard Data
- T1533 Data from Local System
- T1636 Protected User Data
- T1437 Application Layer Protocol
- T1646 Exfiltration Over C2 Channel
- T1471 Data Encrypted for Impact
- T1662 Data Destruction

## Sources

- [Glitch SPY RAT Distributed via Fake Polish App](https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/)
- [Brokewell: do not go broke from new banking malware!](https://www.threatfabric.com/blogs/brokewell-do-not-go-broke-by-new-banking-malware)
- [New 'Brokewell' Android Malware Spread Through Fake Browser Updates](https://thehackernews.com/2024/04/new-brokewell-android-malware-spread.html)
- [New Brokewell malware takes over Android devices, steals data](https://www.bleepingcomputer.com/news/security/new-brokewell-malware-takes-over-android-devices-steals-data/)
- [Android Warning As Brokewell Malware Targets Banking Apps And User Data](https://www.forbes.com/sites/zakdoffman/2024/04/26/google-chrome-free-upgrade-warning-samsung-galaxy-s24-pixel-android/)
- [New 'Brokewell' Android Malware Spread Through Fake Browser Updates](https://owlysec.com/malware-threats/new-brokewell-android-malware-spread-through-fake-browser-updates)
- [Brokewell malware targets Android banking apps](https://medium.com/@zakpatrikcz/brokewell-malware-targets-android-banking-apps-6d5cf4079165)
- [Brokewell - AWAKE Malware Family Reference](https://zahidaz.github.io/awake/malware/families/brokewell/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1195
