5982c3644bfcf7a176fef9dc…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
5982c3644bfcf7a176fef9dce00e5c6b4967b25a381b8603cdc23c41dcbf7bfe
MD5
7c409b4ea3bfe30cdc1ce0bc0c080722

Observed

Families
RatHat
First seen
2026-10-05

APK metadata

Summary

Type
Android · APK
Package
com.spark.wise.gold
Main activity
—
Internal version
40002
Displayed version
4.0.2
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (51)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.ANSWER_PHONE_CALLSandroid.permission.CALL_PHONEandroid.permission.CAMERAandroid.permission.CHANGE_WIFI_STATEandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_CAMERAandroid.permission.FOREGROUND_SERVICE_LOCATIONandroid.permission.FOREGROUND_SERVICE_MEDIA_PROJECTIONandroid.permission.FOREGROUND_SERVICE_MICROPHONEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.GET_ACCOUNTSandroid.permission.INTERNETandroid.permission.MANAGE_EXTERNAL_STORAGEandroid.permission.POST_NOTIFICATIONSandroid.permission.QUERY_ALL_PACKAGESandroid.permission.READ_CALL_LOGandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_AUDIOandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.READ_MEDIA_VISUAL_USER_SELECTEDandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.RECORD_AUDIOandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SCHEDULE_EXACT_ALARMandroid.permission.SEND_SMSandroid.permission.USE_BIOMETRICandroid.permission.USE_CREDENTIALSandroid.permission.USE_EXACT_ALARMandroid.permission.USE_FULL_SCREEN_INTENTandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SECURE_SETTINGSandroid.permission.WRITE_SETTINGScom.coloros.permission.SAFE_COMPONENTcom.google.android.c2dm.permission.RECEIVEcom.miui.permission.START_IN_BACKGROUNDcom.samsung.android.permission.BACKGROUND_START_ACTIVITYcom.spark.wise.gold.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONcom.vivo.abe.permission.CLEAN_NOTIFICATIONcom.vivo.permission.manage.permission.ACCESScom.xiaomi.permission.BACKGROUND_START_ACTIVITYoppo.permission.OPPO_COMPONENT_SAFE

Activities (8)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.spark.wise.gold.activity.AccGuideActivity
  • com.spark.wise.gold.activity.GrantRequestPage
  • com.spark.wise.gold.activity.MainGateway
  • com.spark.wise.gold.activity.SplashGateway
  • com.spark.wise.gold.activity.WakeScreenPage
  • com.spark.wise.gold.features.credential.CredentialPromptActivity
  • com.spark.wise.gold.inject.WebPayloadPage

Services (18)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService
  • com.spark.wise.gold.features.screen.ScreenCastService
  • com.spark.wise.gold.keepalive.AdminKeepAliveDaemon
  • com.spark.wise.gold.keepalive.FcmWakeService
  • com.spark.wise.gold.keepalive.KeepAliveMediaBrowserService
  • com.spark.wise.gold.keepalive.KeepAliveMediaRouteService
  • com.spark.wise.gold.keepalive.KeepAliveTileService
  • com.spark.wise.gold.keepalive.RecoveryJobService
  • com.spark.wise.gold.service.CoreTaskAgent
  • com.spark.wise.gold.service.NotificationListener
  • com.spark.wise.gold.service.PlatformAssistDaemon

Receivers (16)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver
  • com.spark.wise.gold.keepalive.AdminEventReceiver
  • com.spark.wise.gold.keepalive.AlarmKeepAliveReceiver
  • com.spark.wise.gold.keepalive.KeepAliveWidgetProvider
  • com.spark.wise.gold.receiver.BootReceiver
  • com.spark.wise.gold.receiver.PackageEventReceiver

Providers (4)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider
  • com.spark.wise.gold.keepalive.KeepAliveProvider

Intent filters — actions

android.accessibilityservice.AccessibilityServiceandroid.app.action.DEVICE_ADMIN_DISABLEDandroid.app.action.DEVICE_ADMIN_DISABLE_REQUESTEDandroid.app.action.DEVICE_ADMIN_ENABLEDandroid.appwidget.action.APPWIDGET_UPDATEandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.ACTION_SHUTDOWNandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.LOCKED_BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.PACKAGE_ADDEDandroid.intent.action.PACKAGE_CHANGEDandroid.intent.action.PACKAGE_REMOVEDandroid.intent.action.PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.SCREEN_ONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.intent.action.USER_PRESENTandroid.media.MediaRouteProviderServiceandroid.media.browse.MediaBrowserServiceandroid.net.conn.CONNECTIVITY_CHANGEandroid.service.notification.NotificationListenerServiceandroid.service.quicksettings.action.QS_TILEandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.coloros.intent.action.BOOT_COMPLETEDcom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENTcom.htc.intent.action.QUICKBOOT_POWERONcom.huawei.intent.action.BOOT_COMPLETEDcom.huawei.systemmanager.optimize.bootStart.action.BOOTcom.meizu.intent.action.BOOTcom.miui.intent.action.BOOT_COMPLETEDcom.oppo.intent.action.BOOT_COMPLETEDcom.samsung.android.intent.action.BOOT_COMPLETEDcom.vivo.intent.action.BOOT_COMPLETED

Intent filters — categories

android.intent.category.DEFAULT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
www.chengdg.shop/ domain — https RatHat 2026-10-05

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About RatHat

AI-powered Android credential stealer / RAT (Zimperium, Sep 2026) posing as reward or finance apps (Tether, ReelShort lures). Serializes the live Accessibility tree to XML and queries Google Gemini to resolve on-screen targets and drive synthetic clicks. Heavy anti-analysis: a ~61 MB manifest padded with 0x9999 chunks, DEX poisoning, StringFog/StringCrypto, ZIP tampering. Config lives in a ZM26 container under assets/ (zm26_meta.json + .bt files); the C2 is the serverUrl field of server_config.json - plaintext in some builds, ZM26-encrypted in others. The primary FRP tunnel C2 is fetched at runtime by the Go agent liblocal-service.so, with libmedia_codec.so masquerading the frpc client.