Famelack Loader (provisional)
Malware family · 2 sample(s) · 3 indicator record(s) · 2 signing certificate(s)
About Famelack Loader (provisional)
A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels “GOTV” and “TenXun”, each padded with zero-width characters to evade string matching) and shares a common phishing backend at https://famelack.com. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis.
Two observed variants
- A WebView phishing loader (
shell.loader3-layer XOR packer):assets/shell_config.datis XORed with the SHA-256 keystream ofshell_config_key_v1to yield a JSON config, and the encrypted DEX inassets/encrypted/is XOR-decrypted per-layer (keystreamSHA-256(zero-key || layer-index)), stripped and zlib-inflated. The recovered app loadshttps://famelack.comin a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A WebSocket RAT dropper using a custom
SVLT“Vault” container (assets/po70sue2.zip, a header of magicSVLT+ version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-datavault_payload_key). The vault yields a child RAT (app.swift.learn) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects tows://<host>:8080/after an HTTP health check, and also carries thehttps://famelack.combackend.
All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| famelack.com | domain | 75b5b4e8c4e2… | 2026-10-08 |
| famelack.com | domain phishing | 032071c1c92d… | 2026-10-08 |
| 38.60.241.106:8080/ | ip | 032071c1c92d… | 2026-10-08 |