Telegram Phish Proxy (provisional)

Malware family · 7 sample(s) · 9 indicator record(s) · 1 signing certificate(s)

About Telegram Phish Proxy (provisional)

Final payload of a 4-stage “shellapp” native dropper (outer package com.coresoft.studio, horoscope “goroskopys” lure; final payload com.apexware.utils / com.base.template). Each stage decrypts and DexClassLoader-loads the next, so the real code never appears in the installed APK’s dex. The unpacking recovered statically: stage 1→2 uses a native nativeCipher = payload[16:] XOR SHA256(key) with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN “Telegram-bypass” internet blocker) carries a PayloadInstaller that AES-256-CBC-decrypts assets/payload.db; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a ProxyService that opens a WebSocket device-relay C2 and a TelegramPhishActivity that drives a phishing WebView against an operator panel (/api/phish/start, /api/phish/verify, /api/phish/2fa) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack.

Indicators

IndicatorTypeSampleFirst seen
gdebenz.ru domain 3d2b06645150… 2026-10-07
goroskops.com domain 34f261b71257… 2026-10-07
64.188.62.110:9800 ip 34f261b71257… 2026-10-07
64.188.62.110:9800 ip 0da9f39ae576… 2026-10-06
64.188.62.110:9800 ip 32be1aeabebd… 2026-10-07
64.188.62.110:9800 ip 3d2b06645150… 2026-10-07
64.188.62.110:9800 ip 466f8cd95276… 2026-10-06
64.188.62.110:9800 ip 6c9c5f1e08fd… 2026-10-06
94.228.167.90:9800 ip 2c400fc15dff… 2026-10-05