famelack.com

domain phishingC2 not resolving

Tracked by C2 Tracker Ā· Whois queried never

Registration

Registrar
—
Registered
—
Expires
—

DNS

Resolves to
—
Nameservers
—
Status
—

Observed in malware

FamilySample SHA-256RoleFirst seen
Famelack Loader (provisional) 75b5b4e8c4e2… C2 2026-10-08
Famelack Loader (provisional) 032071c1c92d… phishing 2026-10-08

About Famelack Loader (provisional)

A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels "GOTV" and "TenXun", each padded with zero-width characters to evade string matching) and shares a common phishing backend at `https://famelack.com`. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis. **Two observed variants** - A **WebView phishing loader** (`shell.loader` 3-layer XOR packer): `assets/shell_config.dat` is XORed with the SHA-256 keystream of `shell_config_key_v1` to yield a JSON config, and the encrypted DEX in `assets/encrypted/` is XOR-decrypted per-layer (keystream `SHA-256(zero-key || layer-index)`), stripped and zlib-inflated. The recovered app loads `https://famelack.com` in a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A **WebSocket RAT dropper** using a custom `SVLT` "Vault" container (`assets/po70sue2.zip`, a header of magic `SVLT` + version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-data `vault_payload_key`). The vault yields a child RAT (`app.swift.learn`) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects to `ws://<host>:8080/` after an HTTP health check, and also carries the `https://famelack.com` backend. All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional.

Signing certificate

Subject CN
Engineering Team
Issuer CN
Engineering Team
Valid
2026-05-24 → 2053-10-09
Fingerprint
a663b20c2d98fec7ec73267e0d7a211f8444a742c3dd719be02841083984b7e9

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.