Orbit Shop Phish (provisional)

Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s)

About Orbit Shop Phish (provisional)

Phishing/fake-app payload delivered inside an SVLT “shelltemplate” vault dropper (outer package net.ocean.mail; the same vault packer as the AtlasBridge sample, differing only in that the decryption key sits in AndroidManifest application meta-data, vault_payload_key, rather than a plaintext config asset). The decrypted vault carries a vault-config.json, an upgrade-template/ phishing WebView, and a child.apk (org.orbit.shop). The config stats.apiUrl is the telemetry/C2 on a Google typosquat domain (googlems.cc). The loader is Chinese-authored (Chinese log strings; a jobName campaign tag using 群, group). C2 recovered by a full static unpack of the vault; family label provisional, hash-attributed.

Indicators

IndicatorTypeSampleFirst seen
stats.googlems.cc domain 40d1db89934b… 2026-10-08