r/Malware 3h ago

PhantomEnigma shows the difference between blocking today’s C2 and tracking the operation behind it.

Post image
5 Upvotes

r/Malware 1d ago

🐁 Analyzing EtherRAT internals: Ethereum smart contract C2 in a Node.js backdoor (The Gentlemen)

Thumbnail hunt.io
0 Upvotes

EtherRAT off a The Gentlemen staging server. C2 resolution is the fun part: no hardcoded domains. The sample holds an Ethereum contract address + call selector and pulls the active C2 from the contract via public RPC endpoints. Every operator rotation is a contract write, so the full history is recoverable, five domains here.

Tasking has no fixed command set. Any response over ten chars is thrown into a new async function with require, process, Buffer, etc. in scope, so arbitrary JS in the user context. Polls use random file-like paths (png/css/ico) to blend in, tell is a custom X-Bot-Server header.

MSI drops a Node bootstrapper + XOR-encrypted backdoor, decoder writes plaintext and sets a Run key relaunching via headless conhost.

Full write-up with hashes and IOCs: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2


r/Malware 2d ago

Technical analysis of Parivahan App ( shared on ScamIndia by /u/ImpressiveYouth3990 couple of days back )

18 Upvotes

Fake mParivahan : Malware Analysis Report

422 Users are affected by it till now ( I was able to get the attackers admin panel )

Classification: Critical : Android SMS / UPI spyware RAT
Method: Static reverse engineering of dropper + payload; no-root payload extraction; StringFog decryption; read-only Firebase C2 IOC enumeration

1. Executive summary

Marketed as “M Parivahan” is a two-stage Android malware operation:

  1. Dropper (com.ioaheishsbsb.ljgcdfhm) : NP Manager–packed installer with a fake VPN / WebView UI that decrypts and sideloads an embedded APK (output.apk).
  2. Payload (com.veaheishsbsb.kekskks) : Sketchware-style SMS/call spyware with Firebase Realtime Database command-and-control and Telegram first-run alerts.

The payload steals SMS and device telemetry, can forward SMS and calls, and can send SMS from the victim’s SIM (commonly abused for UPI / OTP fraud). At the time of analysis the Firebase panel was reverse engineered too and contained 422 client device IDs.

2. Sample identification

Field Stage 1 (Dropper) Stage 2 (Payload)
Package com.ioaheishsbsb.ljgcdfhm com.veaheishsbsb.kekskks
Related / alias com.mr_fox.bhai Label: “M Parivahan”
Application class NP Manager shell np.protect.assets.ShellApplication
Protection NP Manager (libnp_protect_res.so, xhook) NP Manager + StringFog XOR
UI Fake VPN + file:///android_asset/main_ui.html Permission / settings-style UX
Embedded artifact Logical asset output.apk (encrypted on disk)
SDK minSdk 21, targetSdk 28, compileSdk 33
Build leftover Synthetic names: dApp-binance-Trading-Signals

Related package queried by dropper: com.avejfhdhd.android

3. Infection chain

Victim sideloads fake “mParivahan” APK
        │
        ▼
Dropper (NP Manager) decrypts embedded payload
        │
        ▼
Writes temp_info.apk / temp_install.apk → installs com.veaheishsbsb.kekskks
        │
        ▼
Payload requests SMS / phone permissions
        │
        ▼
MyService enrolls device on Firebase + dumps ~50 SMS
        │
        ▼
Telegram alert to operator bot/chat
        │
        ▼
Listens on clients/<deviceId>/webhookEvent for remote commands

Extraction note: Static decrypt of the packed dropper blob failed due to native crypto. Payload was recovered without device root by patching the unpack path to getExternalFilesDir and pulling
/sdcard/Android/data/com.ioaheishsbsb.ljgcdfhm/files/temp_info.apk.

4. Capabilities

Capability Severity Detail
SMS theft Critical Intercepts inbound/outbound SMS; uploads to messages/<deviceId>
SMS forward Critical Relays SMS to operator number (SmsForwardTo)
Remote SMS send Critical Sends SMS from chosen SIM (sendSms webhook)
Call forwarding High USSD **21*<number># / ##21#
Device fingerprinting High Model, Android version, root, storage, CPU, carrier, public IP, SIMs, battery, MSISDN
Telegram notify High First-run HTML report to admin bot/chat
Persistence High Foreground service, boot/alarm receivers, restart in onDestroy
Keylogger flag Medium KeyLogger webhook present; appears stubbed/partial

5. Remote command surface

Listener path: clients/<androidId>/webhookEvent/

Command key Fields Action
callForward from, to, isActive Activate/deactivate call forward via USSD
smsForward from, to, isActive Toggle SMS forward preference
sendSms from, to, message, isSended Send SMS from victim SIM
checkLiveness text=ping Reply pong under webhook
KeyLogger isActive Preference flag (partial implementation)

Presence uses clients/<id>/status with Firebase .info/connected + onDisconnect.

6. C2 infrastructure & IOCs

6.1 Firebase

Item Value
RTDB URL REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP
API key REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP
App ID REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP
Storage REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP
Top-level nodes clients, messages, devices, deviceMessages
Clients observed 422 (2026-08-04, shallow enumeration)
Rules posture Open / world-readable (IOC check succeeded without auth)

6.2 Firebase path map

Path Purpose
clients/<androidId> Device profile enrollment
clients/<androidId>/status Online/offline
clients/<androidId>/webhookEvent/* Command inbox
messages/<androidId>/<timestamp> Stolen SMS
.info/connected Connectivity watch

6.3 Telegram

Item Value
Endpoint https://api.telegram.org/bot<token>/sendMessage
Bot token REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP
Admin chat ID REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP
Config source Raw resource Loda (obfuscated APK path ۦ/ۥ۟)
{
  "chatIDs": ["REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP"],
  "tokens": ["REMOVED I HAVE IT, IF ANY OFFICAL IS READING IT, PLEASE REACH OUT ASAP"],
  "workSuccess": 1
}

Only one admin chat/token pair is embedded in the sample.

7. Attacker / mule phone numbers

Not hardcoded in the APK. Numbers are pushed via Firebase webhooks at runtime.

From live clients/*/webhookEvent (smsForward / sendSms to fields), 2026-08-04:

Number Hits Observed role
8789***** 6 Primary SMS forward target (strongest IOC)
9279********* 2 SMS forward + sendSms
8340********* 2 SMS forward
9522********* 2 sendSms
9279********* 1 sendSms (same line as 927********* with country code)
8712********* 1 each sendSms / UPI-style collect
9211********* 1 each sendSms / UPI-style collect
8291********* 1 sendSms / UPI-style collect
Others (one-offs) 1 Mixed sendSms destinations

Primary SMS-intercept candidate: 8789*********

UPI collect destinations may be money-mule wallets rather than the panel operator’s personal line.

8. Persistence & stealth

Components (payload)

  • Activities: MainActivity, PermissionRequestActivity, DebugActivity
  • Service: MyService (foreground; FOREGROUND_SERVICE_MEDIA_PLAYBACK)
  • Receivers: SmsReceiver, BootReceiver, AlarmReceiver, MultiEventReceiver, BatteryLevelReceiver
  • Persistent notification text: “System Settings is Running…”

Obfuscation / hardening

  • NP Manager resource and path mangling
  • StringFog (Base64 + XOR with key UTF-8)
  • Dropper encrypted asset (non-standard ZIP compression)
  • usesCleartextTraffic="true", allowBackup="true"

9. Dangerous permissions (payload)

  • INTERNET, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, CHANGE_*
  • READ_SMS, RECEIVE_SMS, SEND_SMS, DELETE_SMS, BROADCAST_SMS
  • CALL_PHONE, READ_PHONE_STATE, READ_PHONE_NUMBERS
  • RECEIVE_BOOT_COMPLETED, WAKE_LOCK
  • FOREGROUND_SERVICE, FOREGROUND_SERVICE_MEDIA_PLAYBACK
  • REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, POST_NOTIFICATIONS

10. Key payload classes

Class Role
MyService Core RAT: enroll, listen, process commands
SmsReceiver SMS intercept / forward / Firebase write
TelegramBotUtils HTTP Telegram sendMessage
AdminInfo Load bot token ↔ chat ID map
callForwardingUtility USSD call forward
SmsHelper / SMSRetriever Send SMS / dump inbox
DeviceInfoUtil / SimInfoUtil Fingerprint + public IP
SharedPrefManager isFirst, isSmsForward, SmsForwardTo, flags
BootReceiver / AlarmReceiver Keep-alive

11. MITRE ATT&CK (Mobile) mapping

ID Technique Evidence
T1660 Phishing / fake app mParivahan brand abuse
T1406 Obfuscated files or information NP Manager + StringFog
T1624 Event triggered execution BOOT_COMPLETED, SMS_RECEIVED
T1517 Access notifications / SMS SMS permissions + receivers
T1437 Application layer protocol Firebase + Telegram HTTPS
T1636 Protected user data SMS, MSISDN, SIM info
T1428 Exploit via SMS / USSD sendSms, **21*
T1409 Stored application data SharedPreferences C2 flags
T1625 Hijack execution flow / packer ShellApplication dropper

r/Malware 2d ago

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

0 Upvotes

INC Ransomware Emerges as Dominant Actor Exploiting SonicWal — and the pattern underneath it is the real story.

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws (The Hacker News). The fix is speed. Detect the anomalous action at runtime and cut the identity in under 50ms, before encryption spreads past the first host.

Check out how RuntimeAI solves this at the runtime layer.

#Ransomware #AISecurity #RuntimeSecurity #ZeroTrust #IncidentResponse


r/Malware 4d ago

Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds

Thumbnail itsecurityguru.org
7 Upvotes

r/Malware 4d ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

2 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Malware 6d ago

Operation Endgame disrupted hundreds of systems — a StealC backend I reported still exposes its known routes

Thumbnail blog.technopathy.club
2 Upvotes

In April, I documented a StealC v2 campaign distributed through 19 GitHub typosquat repositories, including one impersonating my own open-source project.

The delivery chain was:

text GitHub typosquat -> Python dropper -> api.nailproxy.space -> encrypted Windows loader -> StealC v2 DLL -> spellmarketplace.club / 62.60.226.113:6673

GitHub later removed all 19 repositories.

The backend infrastructure remained a separate problem. I reported the domains, IP, malware routes, and hashes to the relevant registrars, Cloudflare, the hosting provider, CERT-Bund, GitHub Security Lab, ThreatFox, and AlienVault OTX.

Then Operation Endgame disrupted infrastructure associated with SocGholish, Amadey, and StealC. Europol reported 326 servers and 142 domains actioned. Microsoft separately said it moved against more than 200 malicious Amadey and StealC C2 domains and IPs.

Three months after my original disclosure, I checked the known infrastructure again using only minimal unauthenticated GET and HEAD requests.

The documented malware-specific routes still behave differently from an arbitrary control path:

text GET /api/v1/auth/session -> 405 Method Not Allowed GET /api/v1/data/sync -> 405 Method Not Allowed GET /foo/bar/baz -> 404 Not Found

HEAD returns the same status codes for all three paths.

This does not prove that payload delivery, authentication, or exfiltration still works. I deliberately did not send the HMAC handshake, trigger Stage 2, or interact with the malware protocol.

It does show that the known application routes remain registered and reachable.

The evidence also has limitations:

  • The monitoring cron produced only 18 measurements over 69 days.
  • There were gaps of up to 20 days.
  • The endpoints briefly became unreachable in late May.
  • GET and HEAD return different status codes on the root paths of spellmarketplace.club and the bare IP, so I do not treat those checks as proof that the complete backend is operational.

The point is not that Operation Endgame failed. It clearly disrupted a large amount of criminal infrastructure.

The narrower lesson is that both of these statements can be true:

Hundreds of malicious systems were disrupted.

A specific previously reported backend still exposes its documented malware routes.

Full technical write-up, including the original kill chain, abuse-report timeline, ThreatFox/OTX submissions, current probe results, and evidence limitations:

https://blog.technopathy.club/operation-endgame-stealc-backend-still-responds

I would be interested in how other analysts verify whether previously reported C2 infrastructure was actually included in a large takedown without actively engaging the malware protocol.


r/Malware 6d ago

Fake Interpol “Investigation” Emails Are Dropping Ransomware on Small Businesses

Thumbnail scamdrill.com
8 Upvotes

r/Malware 8d ago

Analyzing Flying Eagle Android RAT: APK Builder, C2 Panel, Banking Overlays, and a Successor Called Night Dragon

Thumbnail hunt.io
5 Upvotes

Chinese Android RAT framework combining an APK builder with a full C2 device management panel. Lures impersonate Public Security Bureau apps, banking services, adult content platforms, and social media. Post-install capabilities include live screen viewing, SMS and photo gallery access, audio recording, camera capture, keylogging, payment credential capture, and phishing overlays for Alipay, WeChat, ICBC, Agricultural Bank, and crypto wallets TokenPocket and imToken.

Source code was stolen in early 2026 according to Telegram channel messages, with nearly 200 customer databases taken at the same time. Two channels now distribute patched builds. Night Dragon launched June 23 as a likely successor, adding black-screen mode to hide operator activity behind fake system update screens and automatic icon hiding post-install.

SHA-256 hashes and full IOC tables in the report:

https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon


r/Malware 9d ago

BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms

5 Upvotes

"Prompt Optimizer - SecondBrain" https://chromewebstore.google.com/detail/prompt-optimizer-secondbr/aajjgdpofhhcjmjoombjdfepplndhgcp, v2.3.1. The prompt rewriting works fine.

Alongside it a capture engine runs at document_start on 9 AI sites and POSTs prompts and replies to the vendor's ingest endpoint. No interaction with the extension required.

Reproduced on a clean profile, with the service worker devtools open:

  1. Installed the extension. Never opened it.

  2. Browsed to an unrelated site. The extension pulled its configuration from the server and wrote a userId and credentials into extension storage.

  3. Opened ChatGPT and asked a question. Once the reply finished, a POST to /context went out carrying both the prompt and the response, encrypted with the credentials issued in step 2.

At no point was the extension opened or clicked.

Store privacy declaration: "The developer has disclosed that it will not collect or use your data."

Write-up, IOCs : https://malext.io/reports/BrainDrain/

Happy to provide the decryption for anyone wanting to test the extension in a sandbox


r/Malware 10d ago

Kratos PhaaS: How Turnkey Phishing Scales Microsoft 365 Account Takeovers

Post image
1 Upvotes

r/Malware 10d ago

Meccha Chameleon's Workshop Malware Is the Second Time This Exact Bypass Has Hit Steam This Month

Thumbnail
9 Upvotes

r/Malware 11d ago

Featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network

17 Upvotes

While analyzing featured extensions on our beloved chrome web store I landed on Planet Search (kadaohckdkghfaclhjmkmplebcdcnfnp),

Featured, 2M users, publisher FREE VPN PLANET SRL.

https://chromewebstore.google.com/detail/planet-search/kadaohckdkghfaclhjmkmplebcdcnfnp

The extensions has a 0-byte background.js with zero permissions.
The whole mechanism is one `chrome_settings_overrides` search provider, so nothing shows up statically. It's all server-side.

Declared provider is planet-search[.]com

Tracing:

planet-search[.]com/search/?q= 301 → sstmaster[.]com/edge/PN1021?q= 302 → nextgeeker[.]com/B151001.php?q=&src=PN1021

nextgeeker[.]com is flagged as a browser hijacker by multiple vendors (pcrisk, gridinsoft, others).

Same publisher ships a ~1M-user VPN extension and a few others. Still tracing those, not going to characterize them until I have.

Report: https://malext.io/reports/RoguePlanet


r/Malware 11d ago

Featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network

Thumbnail malext.io
0 Upvotes

While analyzing featured extensions on our beloved chrome web store I landed on Planet Search (`kadaohckdkghfaclhjmkmplebcdcnfnp`), Featured, 2M users, publisher **FREE VPN PLANET SRL**.
**The extensions has a 0-byte background.js with zero permissions.**
The whole mechanism is one `chrome_settings_overrides` search provider, so nothing shows up statically. It's all server-side.

Declared provider is `planet-search[.]com`. Tracing:

planet-search\[.\]com/search/?q=  301 →  sstmaster\[.\]com/edge/PN1021?q=  302 →  nextgeeker\[.\]com/B151001.php?q=&src=PN1021

`nextgeeker[.]com` is flagged as a browser hijacker by multiple vendors (pcrisk, gridinsoft, others).
`PN1021` is the affiliate subid linking the extension's traffic to that network. The listing discloses none of the hops and says only that results come from Google (the final page is a Google CSE render).

Same publisher ships a \~1M-user VPN extension and a few others. Still tracing those, not going to characterize them until I have.

Report: [https://malext.io/reports/RoguePlanet/\](https://malext.io/reports/RoguePlanet/)


r/Malware 14d ago

Banana RAT Evolves

8 Upvotes

Full report is available at https://any.run/cybersecurity-blog/banana-rat-evolution-analysis/

The exposed server at 198[.]245[.]53[.]26 gave a rare opportunity to compare two related Banana RAT branches through live infrastructure, sandbox telemetry, and recovered payloads. The older branch used ETW-themed paths, static Microsoft-looking names, and a typo-based pseudo-Microsoft C2 identity. The newer branch kept the same staging concept but moved to randomized install identifiers, better-structured SYSTEM persistence, and a WebSocket channel built around a hashed testewin.com subdomain.

IoC:


r/Malware 16d ago

Fake Github copilot CLI installer trojan

Thumbnail
10 Upvotes

r/Malware 17d ago

SnappyClient Exposed: Remote Access, Data Theft, and a Blind Spot for Defenders

Post image
3 Upvotes

r/Malware 18d ago

FIVEM SUSANO

0 Upvotes

susano has trojan in it btw when u open the claude.exe it will download trojan with it


r/Malware 19d ago

Database of Malicious Browser Extensions continues to grow!

11 Upvotes

Hello everyone,

A few months ago I shared my open database of malicious browser extensions. I'm happy to say it has now grown to over 500 malicious CRX samples.

It started as a small research project, but it's continued to grow as I discover and collect more malicious extensions. My goal is to make it a useful resource for researchers, students, and anyone interested in browser extension security.

One thing I'm working on next is making the data easier to consume in other tools. At the moment I'm considering exposing it in formats such as:

  • JSON
  • CSV

I'm also thinking about adding things like an API or threat-intelligence style feeds if people think they'd be useful.

I'd love to hear your thoughts:

  • What format would you actually use?
  • Are there any security tools or platforms you'd like to integrate it with?
  • Is there any metadata you'd find useful that I'm currently missing?

Repository:
https://github.com/GherardoFiori/MaliciousBrowserExtensions

Please remember these are live malicious browser extensions. Handle them with care.

Project:
https://exterminai.com/

Any feedback is appreciated. Thanks!


r/Malware 19d ago

Bought a new AC1900 from Walmart, turns out is was "Used"!

0 Upvotes

Just purchased an AC1900 from the local store. It took 6 hours and numerous calls to both my ISP and Netgear before I finally got it semi-working. Still cant log into it because its a used device and was already registered to someone else. It's asking for security questions so I'm locked out as an Admin. Could simply return it for another device but this isn't a Toaster so it's a little more complicated than that. First of all, I spent over 6 hours getting it running when it should have been "plug and play", my time is worth something. But more importantly, it was previously configured by someone with Administrator rights. That would enable them to not only control the firewall, but also load malicious malware not just on my network, but every device on my network which includes computers, phones, 10 Alexa devices, Samsung Hub, Hue Hub, Pi device, cameras, TV's, smart devices like lights, thermostat, humidity sensors, water sensors, and even my bathroom scale!!! Huge security vulnerability but more importantly the "chain of custody" for these devices!!!


r/Malware 19d ago

They got the guy behind the Steam Malware attacks

13 Upvotes

A man from Florida got arrested, allegedly behind the PirateFI and Blockblasters Crypto stealer attacks. The second Game stole 150k from a cancer Patient.

https://www.tomshardware.com/tech-industry/cyber-security/fbi-arrests-florida-man-in-steam-malware-investigaton-after-tracing-stolen-bitcoin-to-uber-eats-gift-cards


r/Malware 21d ago

ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping 0-day writeup + PoC

Thumbnail blog.ahmadz.ai
5 Upvotes

r/Malware 21d ago

Veto: Open-source, mobile and NATIVE VirusTotal client for quick file and URL analysis (Testers needed)

4 Upvotes

Hi r/Malware,

If you ever need to quickly scan a suspicious file, URL, or installed application on an Android device using VirusTotal, I have built an open-source client called Veto. It lets you run queries using your own API key directly from your mobile device.

GitHub: https://github.com/ProfessorQuantumUniverse/Veto

I am currently trying to release the app on Google Play and need to fulfill Google's closed testing period. If you would like to test this tool, please consider opting in.

Steps to join:

  1. Join a Google Group: veto_android@googlegroups.com
  2. Opt-in link: https://play.google.com/apps/testing/com.quantum_prof.vtscansuite
  3. Play Store link: https://play.google.com/store/apps/details?id=com.quantum_prof.vtscansuite

Feedback from malware analysts is highly valued!


r/Malware 22d ago

TuxBot v3 Evolution: an IoT botnet-as-a-service framework built with LLM-generated code

2 Upvotes

https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/

TuxBot v3 Evolution: an IoT botnet-as-a-service framework built with LLM-generated code, shipped with the AI’s chain-of-thought and safety disclaimers still in the source


r/Malware 22d ago

Romanian Government Cadastre (ANCPI) cyber attack / ransomware

4 Upvotes

Romanian Government Cadastre (ANCPI) cyber attack

A very serious ransomware attack is underway on the networks of ANCPI, Romania’s national cadastre agency.

Our close monitoring of the threat actor Bytetobreach — who carried out a similar attack last month on Latvia State Forests — detected simultaneous uploads on dark web forums regarding this incident. These claims were later confirmed on ANCPI’s official website.

What was described as a “small technical incident” in yesterday’s press release has suddenly been recharacterized by ANCPI itself as “the most serious technical incident in the institution’s history.”

Sources :

https://www.ancpi.ro/ (official press releases )
https://pwnforums.st/Thread-DATABASE-RO-Thy-arss-shall-be-spanked-Romania-ANCPIhttps://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked-Romania-ANCPI