75b5b4e8c4e20d261c282764…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Famelack Loader (provisional). A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels “GOTV” and “TenXun”, each padded with zero-width characters to evade string matching) and shares a common phishing backend at https://famelack.com. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis.
Two observed variants
- A WebView phishing loader (
shell.loader3-layer XOR packer):assets/shell_config.datis XORed with the SHA-256 keystream ofshell_config_key_v1to yield a JSON config, and the encrypted DEX inassets/encrypted/is XOR-decrypted per-layer (keystreamSHA-256(zero-key || layer-index)), stripped and zlib-inflated. The recovered app loadshttps://famelack.comin a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A WebSocket RAT dropper using a custom
SVLT“Vault” container (assets/po70sue2.zip, a header of magicSVLT+ version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-datavault_payload_key). The vault yields a child RAT (app.swift.learn) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects tows://<host>:8080/after an HTTP health check, and also carries thehttps://famelack.combackend.
All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional. Indicators: https://famelack.com.
Recovered configuration
Identification
- SHA-256
- 75b5b4e8c4e20d261c282764120326f1c541eaa42bb32f6ac7d73efe65e7f2a1
- MD5
- cc1fe6cc8a74370bb5965cd07d03706c
Observed
- Families
- Famelack Loader (provisional)
- First seen
- 2026-10-08
APK metadata
Summary
- Type
- Android · APK
- Package
- org.kqkzn.pkqvxbv
- Main activity
- com.lcobnzv.yptr.MainActivity
- Internal version
- 148
- Displayed version
- 1.4.8
- Min SDK
- 24
- Target SDK
- 36
Signing certificate
- Valid from
- 2026-05-24 14:26:06
- Valid to
- 2053-10-09 14:26:06
- Serial
- 71137444814ee18a
- Thumbprint
- 32564003eac025355ff34ee528f30f58f96eea78
- Subject
- C:US, CN:Engineering Team, L:Memphis, O:Horizon Labs Ltd, ST:Pennsylvania, OU:Services
- Issuer
- C:US, CN:Engineering Team, L:Memphis, O:Horizon Labs Ltd, ST:Pennsylvania, OU:Services
Permissions (391)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| famelack.com | domain | — | https | Famelack Loader (provisional) | 2026-10-08 |
Signing certificate
- Subject CN
- Engineering Team
- Issuer CN
- Engineering Team
- Fingerprint
- a663b20c2d98fec7ec73267e0d7a211f8444a742c3dd719be02841083984b7e9
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Famelack Loader (provisional)
A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels "GOTV" and "TenXun", each padded with zero-width characters to evade string matching) and shares a common phishing backend at `https://famelack.com`. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis. **Two observed variants** - A **WebView phishing loader** (`shell.loader` 3-layer XOR packer): `assets/shell_config.dat` is XORed with the SHA-256 keystream of `shell_config_key_v1` to yield a JSON config, and the encrypted DEX in `assets/encrypted/` is XOR-decrypted per-layer (keystream `SHA-256(zero-key || layer-index)`), stripped and zlib-inflated. The recovered app loads `https://famelack.com` in a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A **WebSocket RAT dropper** using a custom `SVLT` "Vault" container (`assets/po70sue2.zip`, a header of magic `SVLT` + version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-data `vault_payload_key`). The vault yields a child RAT (`app.swift.learn`) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects to `ws://<host>:8080/` after an HTTP health check, and also carries the `https://famelack.com` backend. All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional.