Telegram Phish Proxy (provisional)
Malware family · 7 sample(s) · 9 indicator record(s) · 1 signing certificate(s)
About Telegram Phish Proxy (provisional)
Final payload of a 4-stage “shellapp” native dropper (outer package
com.coresoft.studio, horoscope “goroskopys” lure; final payload com.apexware.utils / com.base.template). Each stage decrypts and DexClassLoader-loads the next, so the real code never appears in the installed APK’s dex. The unpacking recovered statically: stage 1→2 uses a native nativeCipher = payload[16:] XOR SHA256(key) with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN “Telegram-bypass” internet blocker) carries a PayloadInstaller that AES-256-CBC-decrypts assets/payload.db; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a ProxyService that opens a WebSocket device-relay C2 and a TelegramPhishActivity that drives a phishing WebView against an operator panel (/api/phish/start, /api/phish/verify, /api/phish/2fa) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack.Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| gdebenz.ru | domain | 3d2b06645150… | 2026-10-07 |
| goroskops.com | domain | 34f261b71257… | 2026-10-07 |
| 64.188.62.110:9800 | ip | 34f261b71257… | 2026-10-07 |
| 64.188.62.110:9800 | ip | 0da9f39ae576… | 2026-10-06 |
| 64.188.62.110:9800 | ip | 32be1aeabebd… | 2026-10-07 |
| 64.188.62.110:9800 | ip | 3d2b06645150… | 2026-10-07 |
| 64.188.62.110:9800 | ip | 466f8cd95276… | 2026-10-06 |
| 64.188.62.110:9800 | ip | 6c9c5f1e08fd… | 2026-10-06 |
| 94.228.167.90:9800 | ip | 2c400fc15dff… | 2026-10-05 |