Android Installer Dropper (provisional)

Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)

About Android Installer Dropper (provisional)

Android Installer Dropper (provisional) is a label for multi-stage Android droppers whose job is to side-load and install an embedded, encrypted second-stage APK via PackageInstaller, often alongside a VpnService. One observed build (lure More Nutrition) decrypts an asset (XOR plus GZIP) to an in-memory orchestrator DEX that extracts an encrypted archive and installs the embedded b.apk; another ships an encrypted update.enc payload. The final payload and its C2 are recoverable only by dynamic analysis (running the sample and dumping the installed APK), so samples are tracked here pending a dynamic run. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
raw.githubusercontent.com/mohanqquiku/Private-Database/main/lel.pah6y.ypoq.y1i0.bin domain 68335e8d9073… 2026-10-10
raw.githubusercontent.com/mohanqquiku/Private-Database/main/alp.df0rf.elq1.yk1o.bin domain 9e88db0dda56… 2026-10-10

Detected samples without extractable endpoint (2)

Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
52a98b6f60635e19461aa2aa4ba375f5e47388906bc0fe8a4e08ce4adb2e199f - Packed Android dropper (manifest stripped - androguard reports no package; a vpn service keh.kkfkk.dyf.vpn.* is declared). Ships a 4.2 MB encrypted payload assets/update.enc plus assets/di5puti6t8dsi.oam across 15 dex; the real payload is unpacked/installed at runtime. Payload is fully encrypted (entropy ~8.0) and the loader is not fully reversed; C2 not statically recoverable at reasonable cost - requires dynamic analysis. KIV - documented, C2 pending dynamic run. Family label provisional. source 2026-10-09
c31aedd2e16e528951f6e338185a9e220da800119ac3e4fa57de3bc9ba276e40 com.addgqrec.xkc Multi-layer PackageInstaller dropper (outer package com.yxpz.egbhp.uplzvjgnb.npenoart, lure 'More Nutrition'). Chain reversed statically: (1) Application.attachBaseContext decrypts assets/onUQLhOhOz (skip 24 bytes, big-endian int length, per byte (((b^0x38)-28)^0x70)&0xFF, then GZIP) to an in-memory DEX (com.shell.a orchestrator) loaded via InMemoryDexClassLoader and hooked in as the app classloader (ActivityThread mClassLoader reflection); (2) onCreate -> mfvetmxj extracts the assets/xPANlcnWnbe archive to filesDir/assets_i/; (3) com.shell.a installs the embedded assets_i/b.apk via PackageInstaller and runs a PpVpn VpnService. The real banker is b.apk inside xPANlcnWnbe, which is fully stream-encrypted (24-byte header + keystream XOR, no plaintext names/magic). C2 lives in b.apk and is NOT statically recoverable at reasonable cost; requires dynamic analysis (run + dump assets_i/b.apk or hook the installer). KIV - documented, C2 pending dynamic run. Family label provisional. source 2026-10-09