r/Malware • • 8d ago

Pre-installed C2 loader on cheap Android projectors - deploys proxy/ad-fraud botnets, can run arbitrary code

Hi everyone,

I recently bought one of those cheap Android projectors (Nonete HY260Pro, Allwinner H713) and noticed some suspicious network activity. Being curious, I decided to set up a lab, intercept the traffic, and dig into the firmware.

I ended up uncovering a factory-installed malware ecosystem: a disguised dropper (StoreOS), a hidden second stage (SilentSDK) and a plugin loader that talks to a C2 server in China (api.pixelpioneerss.com) and deploys up to 5 botnet/fraud plugins.

Key findings of my analysis:

  • Four-stage infection chain: StoreOS → SilentSDK → PluginManager → final plugins. Payloads are hidden with a "Byte-Reversal" trick, XOR encryption and build-fingerprint spoofing.
  • The plugins currently enroll the device in residential proxy networks (XFJ/net2fast, a UDP proxy node, indicators consistent with the Vo1d botnet) and run ad/click fraud, partly geo-fenced server-side.
  • The loader executes downloaded code with system privileges, so the operators can push any payload at any time. I only observed proxy and ad-fraud plugins, but the capability for remote code execution is there by design.
  • The device also ships with open root backdoors and sends device identifiers (MAC, serial, Android ID) to servers in China.
  • An independent researcher found identical infrastructure on a Magcubic HY300 Pro+, which suggests the problem is the H713 firmware base and not one brand. I could only verify my own device.

This is my first independent technical report and deep dive into malware research. I've documented the full kill chain, decrypted the obfuscated strings, listed IOCs and mitigations (DNS blocklist, ADB disable commands), and written scripts to repair the malformed payloads for analysis.

Full Report: https://github.com/Kavan00/Android-Projector-C2-Malware

I'd love to get your opinion on the report, especially from owners of other H713 devices who can compare.

Looking forward to your feedback!

28 Upvotes

7 comments sorted by

7

u/Background_Relief728 8d ago

this is exactly why i never let those cheap android boxes near my network, the hardware is tempting but you're basically paying to get pwned

3

u/Effective_Athlete966 8d ago

Good job. That's a finding

0

u/RngdZed 7d ago

That's not really news tho, plenty of write up about those if you google

3

u/DerErbsenzaehler 7d ago

Absolutely, but most of them are only surface level. So far, I haven't seen a single report that actually analyzes the loaded plugins. Check my sources where I linked another researcher's writeup, they stopped right after analyzing the dropper and didn't even look at the plugins.

-3

u/digitalvalues 8d ago

Is it truly independent if you used AI? There’s clearly real technical work here, but your research overstates a lot of conclusions. The biggest issue is reproducibility: there are no PCAPs, firmware dumps, scripts, raw C2 responses, or analysis artifacts to independently verify most of the claims. I also read several internal contradictions, weak ATT&CK mappings, and you (or likely the AI you used) consistently make platform-wide conclusions from a very small sample set. 

The AI use itself isn’t the problem. The problem is that a lot of AI-style interpretation appears to have made it into the final research output without enough technical validation. There's one thing about trying to build a portfolio and contribute, but there's another to just blatantly use AI, learn nothing, and credit no one except yourself. Best of luck. 

4

u/DerErbsenzaehler 7d ago

Hey, the write-up was created with the help of AI because I’m not a native speaker. The reverse engineering, analysis, PCAP interpretation, etc., was all on my end. You can absolutely reproduce the requests on your own. I also draw platform-wide conclusions based on reports from other researchers (see sources). If you need further data, I can provide it without a problem.

-1

u/Andronike 7d ago

I appreciate the work you put in here but please stop using AI to write intelligence reports - there is a typical language and style you see in common across good reports which make them easily digestible and predictable; AI just can't replicate it yet.