Famelack Loader (provisional)

Malware family · 2 sample(s) · 3 indicator record(s) · 2 signing certificate(s)

About Famelack Loader (provisional)

A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels “GOTV” and “TenXun”, each padded with zero-width characters to evade string matching) and shares a common phishing backend at https://famelack.com. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis.

Two observed variants

  • A WebView phishing loader (shell.loader 3-layer XOR packer): assets/shell_config.dat is XORed with the SHA-256 keystream of shell_config_key_v1 to yield a JSON config, and the encrypted DEX in assets/encrypted/ is XOR-decrypted per-layer (keystream SHA-256(zero-key || layer-index)), stripped and zlib-inflated. The recovered app loads https://famelack.com in a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs.
  • A WebSocket RAT dropper using a custom SVLT “Vault” container (assets/po70sue2.zip, a header of magic SVLT + version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-data vault_payload_key). The vault yields a child RAT (app.swift.learn) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects to ws://<host>:8080/ after an HTTP health check, and also carries the https://famelack.com backend.

All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
famelack.com domain 75b5b4e8c4e2… 2026-10-08
famelack.com domain phishing 032071c1c92d… 2026-10-08
38.60.241.106:8080/ ip 032071c1c92d… 2026-10-08