be165239e4fe899b1f2eedf6…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

novinarya. Iranian Android banking and crypto stealer (package ir.novinarya), distributed as a fake “Smart System Security” app. The real Basic4Android payload is sealed inside an asset behind a native EPDATA/RC4 packer (loader shell net.swiftnova.bridge); per build the asset name, native library name, RC4 key and key transform are re-randomised while the unpacked 2-dex payload stays byte-identical. It targets ~80 Iranian exchange/wallet and banking apps, steals credentials through a phishing WebView with an injected JavaScript form-grabber, and lifts account numbers, balances and SMS OTP codes via an encrypted 25-bank regex config (X_BANKS). The C2 is never a static string: an encrypted X_ROUTES manifest meta-data value (AES-CBC, key=SHA-256(X_CID)) resolves to a profile on a legitimate marketplace (basalam.com) or github.com, whose bio decrypts to the live rotating C2. Loot is AES-encrypted and POSTed as JSON to that resolved domain. Legitimate dead-drop hosts are never recorded as indicators. Indicators: http://theapi.the-x-services.xyz/.

Recovered configuration

c2_note
Basalam profile "morteza" (id 10118322), not banned at resolution time; bio base64 -> deckey = bio[:10] + AES-256-CBC(SHA-256(deckey), IV prefix) -> C2. Observed in sample be165239e4fe...612e1c9.
c2_resolved_at
2026-10-08
dead_drop_account
m6AJm5
dead_drop_host
services.basalam.com
dead_drop_url
https://services.basalam.com/web/v1/core/user/m6AJm5
loader
net.swiftnova.bridge
mechanism
manifest X_ROUTES (AES-CBC, key=SHA-256(X_CID)) -> marketplace/GitHub bio dead drop -> AES-CBC bio -> rotating C2
package
ir.novinarya
packer
EPDATA native RC4 (32-byte key, 768-byte drop) + zlib; inner 2-dex B4A
reference
STAR Labs / ACT teardown
source_tag
[BASALAM]
x_cid
5i87c5

Identification

SHA-256
be165239e4fe899b1f2eedf6459d363bca4fe6856fda87a63ba5d4e5e612e1c9
MD5
48c5cab842617c00b380d2c4effd8721

Observed

Families
novinarya
First seen
2026-10-07

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
theapi.the-x-services.xyz/ domain - http novinarya 2026-10-07

Signing certificate

Subject CN
-
Issuer CN
-
Fingerprint
022a1ed9feb0e6c9826df99c58350b7789a71ad51f142f40449f91d58c0278c1

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Novinarya

Iranian Android banking and crypto stealer (package ir.novinarya), distributed as a fake "Smart System Security" app. The real Basic4Android payload is sealed inside an asset behind a native EPDATA/RC4 packer (loader shell net.swiftnova.bridge); per build the asset name, native library name, RC4 key and key transform are re-randomised while the unpacked 2-dex payload stays byte-identical. It targets ~80 Iranian exchange/wallet and banking apps, steals credentials through a phishing WebView with an injected JavaScript form-grabber, and lifts account numbers, balances and SMS OTP codes via an encrypted 25-bank regex config (X_BANKS). The C2 is never a static string: an encrypted X_ROUTES manifest meta-data value (AES-CBC, key=SHA-256(X_CID)) resolves to a profile on a legitimate marketplace (basalam.com) or github.com, whose bio decrypts to the live rotating C2. Loot is AES-encrypted and POSTed as JSON to that resolved domain. Legitimate dead-drop hosts are never recorded as indicators.