032071c1c92d900f4a6db146…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Famelack Loader (provisional). A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels “GOTV” and “TenXun”, each padded with zero-width characters to evade string matching) and shares a common phishing backend at https://famelack.com. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis.
Two observed variants
- A WebView phishing loader (
shell.loader3-layer XOR packer):assets/shell_config.datis XORed with the SHA-256 keystream ofshell_config_key_v1to yield a JSON config, and the encrypted DEX inassets/encrypted/is XOR-decrypted per-layer (keystreamSHA-256(zero-key || layer-index)), stripped and zlib-inflated. The recovered app loadshttps://famelack.comin a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A WebSocket RAT dropper using a custom
SVLT“Vault” container (assets/po70sue2.zip, a header of magicSVLT+ version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-datavault_payload_key). The vault yields a child RAT (app.swift.learn) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects tows://<host>:8080/after an HTTP health check, and also carries thehttps://famelack.combackend.
All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional. Indicators: ws://38.60.241.106:8080/, https://famelack.com.
Recovered configuration
Identification
- SHA-256
- 032071c1c92d900f4a6db14625161a5a0bdd184c9fc536f082be98c7047296b2
- MD5
- e71f91224a8d87c4cb67a2b239835c73
Observed
- Families
- Famelack Loader (provisional)
- First seen
- 2026-10-08
APK metadata
Summary
- Type
- Android · APK
- Package
- com.maple.life
- Main activity
- com.maple.life.NetworkCommonService
- Internal version
- 900349776
- Displayed version
- 2.82.225
- Min SDK
- 24
- Target SDK
- 36
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
- Subject email
- android@android.com
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Permissions (184)
Intent filters — actions
Intent filters — categories
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| famelack.com | domain | — | https | Famelack Loader (provisional) | 2026-10-08 |
| 38.60.241.106/ | ip | 8080 | ws | Famelack Loader (provisional) | 2026-10-08 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Famelack Loader (provisional)
A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels "GOTV" and "TenXun", each padded with zero-width characters to evade string matching) and shares a common phishing backend at `https://famelack.com`. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis. **Two observed variants** - A **WebView phishing loader** (`shell.loader` 3-layer XOR packer): `assets/shell_config.dat` is XORed with the SHA-256 keystream of `shell_config_key_v1` to yield a JSON config, and the encrypted DEX in `assets/encrypted/` is XOR-decrypted per-layer (keystream `SHA-256(zero-key || layer-index)`), stripped and zlib-inflated. The recovered app loads `https://famelack.com` in a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A **WebSocket RAT dropper** using a custom `SVLT` "Vault" container (`assets/po70sue2.zip`, a header of magic `SVLT` + version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-data `vault_payload_key`). The vault yields a child RAT (`app.swift.learn`) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects to `ws://<host>:8080/` after an HTTP health check, and also carries the `https://famelack.com` backend. All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional.