984ebc258c100ca287510c50…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
SyamRAT (provisional). Commodity Indonesian Android RAT distributed under utility/“booster” lures
(e.g. package com.pt.sejahtera, label “pelancar hp” — Indonesian for “phone
booster”). The build ships a plaintext assets/config.json naming the operator
backend, and abuses AccessibilityService + MediaProjection for remote
control, overlay injection and live screen capture. A bundled native module
(libnuker.so / assets/nuker, an ELF) provides the screen-stream/VNC
component. Live control runs over Socket.IO to the base_url in the config.
How the C2 is recovered: config.json is cleartext, so the decoder reads
base_url directly (binary-verified). The webview_url (commonly
https://www.google.com) and logo_url (image CDNs such as catbox.moe) are
victim-facing decoys and are not recorded as C2. The operator username,
session_id and per-build uid (from assets/uid.json) are captured as
attribution. Family label is provisional — this is a builder kit, not a single
actor. Indicators: https://syamrat.otax.fun.
Recovered configuration
Identification
- SHA-256
- 984ebc258c100ca287510c50d2e50e5fa0f7364bb354427d53d0148712ea09fc
- MD5
- b6224053aeb60de3663a0e82b13f8097
Observed
- Families
- SyamRAT (provisional)
- First seen
- 2026-08-21
APK metadata
Summary
- Type
- Android · APK
- Package
- com.pt.sejahtera
- Main activity
- com.pt.sejahtera.SplashActivity
- Internal version
- 9
- Displayed version
- 1.3.4-silentcam
- Min SDK
- 24
- Target SDK
- 34
Signing certificate
- Valid from
- 2016-10-23 20:10:05
- Valid to
- 2044-03-10 20:10:05
- Serial
- 56c1a15
- Thumbprint
- 5d08264b44e0e53fbccc70b4f016474cc6c5ab5c
- Subject
- C:US, CN:Android Debug, L:US, O:US, ST:US, OU:Android
- Issuer
- C:US, CN:Android Debug, L:US, O:US, ST:US, OU:Android
Permissions (40)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| syamrat.otax.fun | domain | — | https | SyamRAT (provisional) | 2026-08-21 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About SyamRAT (provisional)
Commodity **Indonesian Android RAT** distributed under utility/"booster" lures (e.g. package `com.pt.sejahtera`, label *"pelancar hp"* — Indonesian for "phone booster"). The build ships a plaintext `assets/config.json` naming the operator backend, and abuses **AccessibilityService** + **MediaProjection** for remote control, overlay injection and live screen capture. A bundled native module (`libnuker.so` / `assets/nuker`, an ELF) provides the screen-stream/VNC component. Live control runs over **Socket.IO** to the `base_url` in the config. How the C2 is recovered: `config.json` is cleartext, so the decoder reads `base_url` directly (binary-verified). The `webview_url` (commonly `https://www.google.com`) and `logo_url` (image CDNs such as catbox.moe) are victim-facing decoys and are **not** recorded as C2. The operator `username`, `session_id` and per-build `uid` (from `assets/uid.json`) are captured as attribution. Family label is provisional — this is a builder kit, not a single actor.