12b72de4d7869e4f27ef9a06…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Black Hawk. An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a “Rakuten account protection” app (label “楽天アカウント保護”, padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family’s extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords. Indicators: https://tnt.freedomdf.xyz.

Recovered configuration

aes_key
93c581dc804d87f943130a671a87097baeb54c76a280e55edf1fbfcf0f8ea44a
inner_package
com.trend.fast.love

Source: native XOR packer (libsa.so) -> inner dex Cf config

Identification

SHA-256
12b72de4d7869e4f27ef9a06e792c11defd0e5e7e57e9b6a0d1b97f2ac9a5ace
MD5
4786ded6d1ddfd89a19ef1461956e915

Observed

Families
Black Hawk
First seen
2026-10-08

APK metadata

Summary

Type
Android · APK
Package
org.fast.clean.work
Main activity
org.fast.clean.work.MainActivity
Internal version
20890
Displayed version
2.8.90
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (5)

Decoy loader shell — the real permission set is under Unpacked payload below.

Activities (2)

  • org.fast.clean.work.MainActivity
  • org.fast.clean.work.Wv

Services (1)

  • org.fast.clean.work.Bv

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • org.fast.clean.work.Ir

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters — actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEorg.fast.clean.work.INSTALL_COMPLETE

Unpacked payload

The real payload hidden inside the packer, recovered by unwrapping the sample (Black Hawk native XOR packer (installed banker APK)). This is the actual capability set the malware runs with — the APK metadata above is only the decoy loader shell.

Summary

Package
com.trend.fast.love
Main activity
—
Internal version
10718
Displayed version
1.7.18
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (39)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CAMERAandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_CAMERAandroid.permission.FOREGROUND_SERVICE_LOCATIONandroid.permission.FOREGROUND_SERVICE_MEDIA_PROJECTIONandroid.permission.FOREGROUND_SERVICE_MICROPHONEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.GET_ACCOUNTSandroid.permission.INTERNETandroid.permission.MANAGE_EXTERNAL_STORAGEandroid.permission.POST_NOTIFICATIONSandroid.permission.QUERY_ALL_PACKAGESandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_AUDIOandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.READ_MEDIA_VISUAL_USER_SELECTEDandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.RECORD_AUDIOandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SCHEDULE_EXACT_ALARMandroid.permission.SEND_SMSandroid.permission.USE_BIOMETRICandroid.permission.USE_EXACT_ALARMandroid.permission.USE_FULL_SCREEN_INTENTandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SECURE_SETTINGSandroid.permission.WRITE_SETTINGScom.google.android.c2dm.permission.RECEIVEcom.trend.fast.love.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (8)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.trend.fast.love.activity.AccGuideActivity
  • com.trend.fast.love.activity.GrantRequestPage
  • com.trend.fast.love.activity.MainGateway
  • com.trend.fast.love.activity.SplashGateway
  • com.trend.fast.love.activity.WakeScreenPage
  • com.trend.fast.love.features.credential.CredentialPromptActivity
  • com.trend.fast.love.inject.WebPayloadPage

Services (17)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService
  • com.trend.fast.love.features.screen.ScreenCastService
  • com.trend.fast.love.keepalive.AdminKeepAliveDaemon
  • com.trend.fast.love.keepalive.FcmWakeService
  • com.trend.fast.love.keepalive.KeepAliveMediaBrowserService
  • com.trend.fast.love.keepalive.KeepAliveMediaRouteService
  • com.trend.fast.love.keepalive.KeepAliveTileService
  • com.trend.fast.love.keepalive.RecoveryJobService
  • com.trend.fast.love.service.CoreTaskAgent
  • com.trend.fast.love.service.PlatformAssistDaemon

Receivers (16)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver
  • com.trend.fast.love.keepalive.AdminEventReceiver
  • com.trend.fast.love.keepalive.AlarmKeepAliveReceiver
  • com.trend.fast.love.keepalive.KeepAliveWidgetProvider
  • com.trend.fast.love.receiver.BootReceiver
  • com.trend.fast.love.receiver.PackageEventReceiver

Providers (4)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider
  • com.trend.fast.love.keepalive.KeepAliveProvider

Intent filters — actions

android.accessibilityservice.AccessibilityServiceandroid.app.action.DEVICE_ADMIN_DISABLEDandroid.app.action.DEVICE_ADMIN_DISABLE_REQUESTEDandroid.app.action.DEVICE_ADMIN_ENABLEDandroid.appwidget.action.APPWIDGET_UPDATEandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.ACTION_SHUTDOWNandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.LOCKED_BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.PACKAGE_ADDEDandroid.intent.action.PACKAGE_CHANGEDandroid.intent.action.PACKAGE_REMOVEDandroid.intent.action.PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.SCREEN_ONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.intent.action.USER_PRESENTandroid.media.MediaRouteProviderServiceandroid.media.browse.MediaBrowserServiceandroid.net.conn.CONNECTIVITY_CHANGEandroid.service.quicksettings.action.QS_TILEandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
tnt.freedomdf.xyz domain — https Black Hawk 2026-10-08

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.