06a47ef466f1637460cbe1e2…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Flutter Banking Overlay (provisional). A Flutter-built Android banking trojan distributed as a betting/casino app (observed package com.apkhadesbet, a “hadesbet” gambling lure). Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so instead of to normal Java/DEX code, so both the behaviour and the C2 live in that .so file rather than in the usual Android code. Indicators: https://n1cdatadev-nrfru.ondigitalocean.app, https://data.ncup.team.

Recovered configuration

bundled_payload
assets/bound_payload.apk
overlay_targets
bmo.com, bmodigitalbanking.com, cibc.com, desjardins.com, dominobank.com, dominotoronto.com, muchbetter.com, rbc.com, royalbank.com

Source: backend base URL in Flutter libapp.so

Flutter banking-overlay trojan: bundles a second payload APK and uses flutter_inappwebview to phish bank logins via fake overlays. C2 is a hardcoded PaaS backend in libapp.so, distinct from the overlay-target banks and attribution SDKs. Label provisional.

Identification

SHA-256
06a47ef466f1637460cbe1e24f48cca88aee7b2729c3993cc044c8c8f87bdf6c
MD5
79be4ebd108d81c6e769e7ec87afa192

Observed

Families
Flutter Banking Overlay (provisional)
First seen
2026-08-26

APK metadata

Summary

Type
Android · APK
Package
com.apkhadesbet
Main activity
com.apkhadesbet.MainActivity
Internal version
1
Displayed version
1.0.0
Min SDK
24
Target SDK
36

Permissions (15)

android.permission.ACCESS_ADSERVICES_ATTRIBUTIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.CAMERAandroid.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.RECORD_AUDIOandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEcom.apkhadesbet.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONcom.google.android.c2dm.permission.RECEIVEcom.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICEcom.google.android.gms.permission.AD_IDcom.huawei.appmarket.service.commondata.permission.GET_COMMON_DATAcom.samsung.android.mapsagent.permission.READ_APP_INFO

Activities (9)

  • com.apkhadesbet.MainActivity
  • com.google.android.gms.common.api.GoogleApiActivity
  • com.google.android.play.core.common.PlayCoreDialogWrapperActivity
  • com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.ChromeCustomTabsActivity
  • com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.ChromeCustomTabsActivitySingleInstance
  • com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.TrustedWebActivity
  • com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.TrustedWebActivitySingleInstance
  • com.pichillilorenzo.flutter_inappwebview_android.in_app_browser.InAppBrowserActivity
  • io.flutter.plugins.urllauncher.WebViewActivity

Services (6)

  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService
  • io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingBackgroundService
  • io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingService

Receivers (5)

  • androidx.profileinstaller.ProfileInstallReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver
  • com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.ActionBroadcastReceiver
  • io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingReceiver

Providers (3)

  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider
  • io.flutter.plugins.firebase.messaging.FlutterFirebaseMessagingInitProvider

Intent filters — actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEcom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENT

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
data.ncup.team domain — https Flutter Banking Overlay (provisional) 2026-08-26
n1cdatadev-nrfru.ondigitalocean.app domain — https Flutter Banking Overlay (provisional) 2026-08-26

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Flutter Banking Overlay (provisional)

A **Flutter**-built Android banking trojan distributed as a betting/casino app (observed package `com.apkhadesbet`, a "hadesbet" gambling lure). Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` instead of to normal Java/DEX code, so both the behaviour and the C2 live in that `.so` file rather than in the usual Android code. **What it does** - Bundles a second payload APK (`assets/bound_payload.apk`) that it installs/loads. - Uses `flutter_inappwebview` (an embedded browser) to pop **fake bank-login overlays** on top of real apps and harvest credentials. Observed targeting **Canadian** institutions - RBC (`royalbank.com`), BMO (`bmodigitalbanking.com`), CIBC, Desjardins, Domino - plus the **MuchBetter** wallet (`muchbetter.com`), behind gambling lures (`hadesbet3.com`, `betonredcasinobe.com`). **How the C2 is recovered (binary-only)** The operator backend is a single hardcoded **HTTPS** base URL compiled into the Dart snapshot `libapp.so`, read directly from that file's string pool. It sits on a throwaway PaaS host (a `*.ondigitalocean.app` subdomain) and is deliberately kept separate from (a) the overlay-target **bank** domains the trojan phishes and (b) the attribution SDKs it ships (AppsFlyer / OneLink); the decoder filters those out so only the real operator backend is recorded. Family label provisional.