famelack.com
domain phishingC2Tracked by C2 Tracker Ā· Whois queried never
Registration
- Registrar
- ā
- Registered
- ā
- Expires
- ā
DNS
- Resolves to
- ā
- Nameservers
- ā
- Status
- ā
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Famelack Loader (provisional) | 75b5b4e8c4e2⦠| C2 | 2026-10-08 |
| Famelack Loader (provisional) | 032071c1c92d⦠| phishing | 2026-10-08 |
About Famelack Loader (provisional)
A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels "GOTV" and "TenXun", each padded with zero-width characters to evade string matching) and shares a common phishing backend at `https://famelack.com`. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis. **Two observed variants** - A **WebView phishing loader** (`shell.loader` 3-layer XOR packer): `assets/shell_config.dat` is XORed with the SHA-256 keystream of `shell_config_key_v1` to yield a JSON config, and the encrypted DEX in `assets/encrypted/` is XOR-decrypted per-layer (keystream `SHA-256(zero-key || layer-index)`), stripped and zlib-inflated. The recovered app loads `https://famelack.com` in a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A **WebSocket RAT dropper** using a custom `SVLT` "Vault" container (`assets/po70sue2.zip`, a header of magic `SVLT` + version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-data `vault_payload_key`). The vault yields a child RAT (`app.swift.learn`) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects to `ws://<host>:8080/` after an HTTP health check, and also carries the `https://famelack.com` backend. All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional.
Signing certificate
- Subject CN
- Engineering Team
- Issuer CN
- Engineering Team
- Valid
- 2026-05-24 ā 2053-10-09
- Fingerprint
- a663b20c2d98fec7ec73267e0d7a211f8444a742c3dd719be02841083984b7e9
Other samples signed with this certificate? That's a lead worth checking ā but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.