06a47ef466f1637460cbe1e2…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
com.apkhadesbet, a “hadesbet” gambling lure). Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so instead of to normal Java/DEX code, so both the behaviour and the C2 live in that .so file rather than in the usual Android code. Indicators: https://n1cdatadev-nrfru.ondigitalocean.app, https://data.ncup.team.Recovered configuration
Source: backend base URL in Flutter libapp.so
Flutter banking-overlay trojan: bundles a second payload APK and uses flutter_inappwebview to phish bank logins via fake overlays. C2 is a hardcoded PaaS backend in libapp.so, distinct from the overlay-target banks and attribution SDKs. Label provisional.
Identification
- SHA-256
- 06a47ef466f1637460cbe1e24f48cca88aee7b2729c3993cc044c8c8f87bdf6c
- MD5
- 79be4ebd108d81c6e769e7ec87afa192
Observed
- Families
- Flutter Banking Overlay (provisional)
- First seen
- 2026-08-26
APK metadata
Summary
- Type
- Android · APK
- Package
- com.apkhadesbet
- Main activity
- com.apkhadesbet.MainActivity
- Internal version
- 1
- Displayed version
- 1.0.0
- Min SDK
- 24
- Target SDK
- 36
Permissions (15)
Intent filters — actions
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| data.ncup.team | domain | — | https | Flutter Banking Overlay (provisional) | 2026-08-26 |
| n1cdatadev-nrfru.ondigitalocean.app | domain | — | https | Flutter Banking Overlay (provisional) | 2026-08-26 |
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Flutter Banking Overlay (provisional)
A **Flutter**-built Android banking trojan distributed as a betting/casino app (observed package `com.apkhadesbet`, a "hadesbet" gambling lure). Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` instead of to normal Java/DEX code, so both the behaviour and the C2 live in that `.so` file rather than in the usual Android code. **What it does** - Bundles a second payload APK (`assets/bound_payload.apk`) that it installs/loads. - Uses `flutter_inappwebview` (an embedded browser) to pop **fake bank-login overlays** on top of real apps and harvest credentials. Observed targeting **Canadian** institutions - RBC (`royalbank.com`), BMO (`bmodigitalbanking.com`), CIBC, Desjardins, Domino - plus the **MuchBetter** wallet (`muchbetter.com`), behind gambling lures (`hadesbet3.com`, `betonredcasinobe.com`). **How the C2 is recovered (binary-only)** The operator backend is a single hardcoded **HTTPS** base URL compiled into the Dart snapshot `libapp.so`, read directly from that file's string pool. It sits on a throwaway PaaS host (a `*.ondigitalocean.app` subdomain) and is deliberately kept separate from (a) the overlay-target **bank** domains the trojan phishes and (b) the attribution SDKs it ships (AppsFlyer / OneLink); the decoder filters those out so only the real operator backend is recorded. Family label provisional.