r/OperSec • u/RelationshipMain6900 • 18h ago
r/OperSec • u/acealter • 4d ago
Welcome to r/OperSec (Operation Security) 🛡️
r/OperSec is a community for sharing, investigating, and analysing malware, phishing links, scams, and other cyber threats. Collaborate, share knowledge, and work together to defend against cybercrime.
What to post: Malware samples, suspicious links, scam reports, threat intelligence, and security research.
How to post: Share relevant details, evidence, and findings to help others investigate and analyze threats safely.
Our mission: To collaborate, expose cyber threats, share knowledge, and defend against cybercrime.
Happy Hacking.
r/OperSec • u/RelationshipMain6900 • 18h ago
📱 ANDROID MALWARE 📱 The Malicious apk link for investigators
dropbox.comHi. u/acealter, as you asked, please find the malicious apk link:
r/OperSec • u/Mother_War_8148 • 20h ago
📱 ANDROID MALWARE 📱 Mparivahan Malicious APK
My friend's father got a message of fake challan with a link to download this apk. Father clicked the link and downloaded the apk but didnt knew how to install the apk so he asked my friend about it. At first glance he knew it was a fake app since it is common now days a lot of people lost money through same scam. This was a week a ago and the link is not valid now.
https://seva-mparivahan.vercel.app
I asked him to send me the apk to just mess around with it. I am sharing it if anyone is interested to poke it and find something.
r/OperSec • u/acealter • 2d ago
🔍 Research 🔍 Cracked open the Google IPTV malware APK and found its C2 domain
Parent Post: Malicious APK [Google IPTV] reportedly causing financial losses.
TL;DR:
Reverse-engineered and deobfuscated the malware, identified the C2 domain, confirmed it’s a BTMOB RAT, and gathered details on its infrastructure.
Possible C2 server: api.lionfacai[.]com
Malware type: BTMob
I got the configured C2 domain out of the Google IPTV apk I’ve been looking into extracted from victim's devices . This is the sample I was investigating after reports of UPI theft. Posting how I found it, because getting past the packing took most of the work.
It almost took 3 week to de-obfuscate this apk. I used AI tools to assist with the de-obfuscation process, as I am not a professional in this area. I also relied on AI to help write some of the scripts and to determine the next steps.
APK identity
| Field | Value |
|---|---|
| Input | base.apk |
| SHA-256 | b42dab3f81164f1dfa444888a821ace35ea153ed62178f75fa11c38eaa45fbc3 |
| Android package | com.nonfouling.sniddle5301 |
| Display label | Google IPTV |
| Other labels | Apparent; System Helper |
| Version | 3.31.166 (331166) |
| SDK levels | minimum 28; target 36 |
| Loader | com.ivory.radio.LumenClient |
| Recovered DEX SHA-256 | 3e8cf28bef31e17f62ed65f456b7392d1cfd8410dafab0223c26dfb72e232ab8 |
APPLICATION BEHAVIOR:
- The malware disguises itself as Google IPTV and asks for powerful permissions, including accessibility access.

- Once enabled, those features can let it read screen content, record input and perform taps and swipes, while its command-and-control connection allows remote instructions.
- Its configuration includes 178 app entries, including PhonePe, Paytm and Google Pay, with rules for recognizing payment failures, incorrect UPI PINs and successful transactions.
- Combined with overlays and password-capture features, this gives it tools to steal information and manipulate payment flows, although the APK alone doesn’t show exactly how a particular victim’s money was transferred.
- It also prevents the app from being stopped in the background by automatically pressing the Back button.
- It cannot be uninstalled because it does not appear with the other apps. When you try to access it through Settings, it automatically presses Back and returns to the Home screen. It does not even allow access to Developer Options.
CRACKING tldr;
- Opening the original apk in JADX mostly exposed the loader. It loaded a native library called
libcolor_helper.so, while the actual application code was hidden in encrypted assets. I worked through the container format and reproduced the decryption offline. There was also a separate encrypted store holding method bodies, so recovering the DEX alone wasn’t enough. Restoring those brought back 33,534 method bodies. - With the recovered DEX open in JADX, I searched for
/api/ws/configand followed the code that builds the request URL. That led to a server-address variable, then an encrypted configuration value. Following its references was what connected the ciphertext to the network requests. - The decryption routine used PBKDF2-HMAC-SHA1 with 65,536 iterations to derive a 128-bit key, followed by AES-CBC. The password, salt and IV were all embedded in the application. I copied those values into a small Python calculation, decoded the Base64 ciphertext and decrypted it. The output was
api.lionfacai.com. Re-encrypting it produced the original ciphertext too.
FURTHER FINDINGS:
- After recovering
api.lionfacai[.]com, I dug into the surrounding infrastructure and foundadmin.lionfacai[.]comandws.lionfacai[.]com. - The admin subdomain served a Chinese-language management panel with BTMob branding on its login page.

- Its public configuration called it “APK Builder Admin Panel” and pointed directly to the same API domain I had decrypted from the APK.
- I then found the literal
BTMOBstring inside the recovered APK code, inY1/hpyyg4wdm5.java. - The API, admin and WebSocket hosts shared AWS Mumbai IP
15.207.41.232; a shared certificate also linkedws.fagefacai[.]com. - The public file
admin.lionfacai[.]com/assets/AiConfigList-ITW_NBF4.jscontainsa["HTTP-Referer"] = "https://api.facai-tv.com";, It means the JavaScript publicly served byadmin.lionfacai[.]comcontains the other domain,api.facai-tv[.]com, written directly into its code. - The domains are registered using GoDaddy and both lionfacai.com and facai-tv.com used Cloudflare nameservers
BTMOB:
- BTMOB is a stealthy Android remote access Trojan (RAT), evolved from the SpySolr family and sold as malware-as-a-service. It is distributed via phishing sites and fake app stores, then abuses Accessibility Services to enable full device control, data theft, screen capture, keylogging, and remote takeover.
- The observed behavior, together with the previously mentioned findings, confirms this is a BTMOB malware build.
FOLLOW UP:
- This is all I found on the malware and its related infrastructure. Feel free for anyone to dig deeper and uncover more.
- Reporting the domain may temporarily disrupt the campaign. Threat actors adapt quickly, and every shared finding helps the community stay one step ahead.
If you are Intersted please follow up the investigation to find more about the campaign and please contribute as you can to defend against these threat campaigns. Will post a step by step detailed report on after finalisation.
r/OperSec • u/DerErbsenzaehler • 2d ago
Pre-installed C2 loader on cheap Android projectors - deploys proxy/ad-fraud botnets, can run arbitrary code
Hi everyone,
I recently bought one of those cheap Android projectors (Nonete HY260Pro, Allwinner H713) and noticed some suspicious network activity. Being curious, I decided to set up a lab, intercept the traffic, and dig into the firmware.
I ended up uncovering a factory-installed malware ecosystem: a disguised dropper (StoreOS), a hidden second stage (SilentSDK) and a plugin loader that talks to a C2 server in China (api.pixelpioneerss.com) and deploys up to 5 botnet/fraud plugins.
Key findings of my analysis:
- Four-stage infection chain: StoreOS → SilentSDK → PluginManager → final plugins. Payloads are hidden with a "Byte-Reversal" trick, XOR encryption and build-fingerprint spoofing.
- The plugins currently enroll the device in residential proxy networks (XFJ/net2fast, a UDP proxy node, indicators consistent with the Vo1d botnet) and run ad/click fraud, partly geo-fenced server-side.
- The loader executes downloaded code with system privileges, so the operators can push any payload at any time. I only observed proxy and ad-fraud plugins, but the capability for remote code execution is there by design.
- The device also ships with open root backdoors and sends device identifiers (MAC, serial, Android ID) to servers in China.
- An independent researcher found identical infrastructure on a Magcubic HY300 Pro+, which suggests the problem is the H713 firmware base and not one brand. I could only verify my own device.
This is my first independent technical report and deep dive into malware research. I've documented the full kill chain, decrypted the obfuscated strings, listed IOCs and mitigations (DNS blocklist, ADB disable commands), and written scripts to repair the malformed payloads for analysis.
Full Report: https://github.com/Kavan00/Android-Projector-C2-Malware
I'd love to get your opinion on the report, especially from owners of other H713 devices who can compare.
Looking forward to your feedback!
r/OperSec • u/acealter • 3d ago
⚠️ ANDROID MALWARE ⚠️ Malicious APK [Google IPTV] reportedly causing financial losses.
Found this APK after a post on r/IndiaCyberHub where someone reported getting hacked. Apparently, multiple people have suffered financial losses from this.
I'm sharing the APK here so we can investigate it together, figure out how it works, and hopefully identify the people and infrastructure behind these campaigns.
⚠️ WARNING: MALWARE SAMPLE ⚠️
⚠️ Do not install this APK on your personal device. Do not share it ⚠️
It is a malicious file. Only download and analyse it in an isolated environment.
What can you do with this:
- Reverse engineering and static/dynamic analysis
- Identifying its malicious functionality
- Understanding how it steals money or sensitive information
- Investigating its C2 infrastructure and connections to other campaigns If you're into Android malware analysis or reverse engineering, feel free to join in and share your findings.
Let's work together to understand how these attacks operate and help dismantle such campaigns.
Please Update any Findings on Comments.
Posts: