c734e944db5634b5ebf6bde5…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

RatHat. AI-powered Android credential stealer / RAT (Zimperium, Sep 2026) posing as reward or finance apps (Tether, ReelShort lures). It serialises the live Accessibility tree to XML and queries Google Gemini to resolve on-screen targets and drive synthetic clicks — letting it read and operate banking and wallet apps on the victim’s behalf without a human operator. Heavily hardened against analysis: a ~61 MB AndroidManifest.xml padded with 0x9999-byte junk chunks, DEX poisoning (deliberately malformed bytecode that breaks naïve disassemblers), StringFog/StringCrypto string encryption and ZIP tampering. Configuration lives in a ZM26 container under assets/ — RatHat’s own encrypted-blob format: a 4-byte ZM26 magic, an 8-byte salt, then the payload XOR’d with a repeating 24-byte key (the per-sample xor_key from assets/zm26_meta.json, concatenated with that salt). The C2 is the serverUrl field of server_config.json — recoverable in plaintext in some builds, ZM26-encrypted in others. The primary FRP tunnel C2 is not a static indicator: it is fetched at runtime by the bundled Go agent liblocal-service.so, while libmedia_codec.so masquerades as the frpc tunnel client. Indicators: wss://mrcrack65.de5.net/.

Recovered configuration

buildtime
2026-06-22T19:04:11+08:00
geminiapikey
AQ.Ab8RN6ILQvb_db-vvjKQV5kOTB8gICPm0dmunDyRVSxGnI4xnA
reference
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts

Source: plaintext:server_config.json

RatHat. serverUrl is the registration/WebSocket C2; the primary FRP tunnel C2 is runtime-fetched by liblocal-service.so and is not a static IOC.

Identification

SHA-256
c734e944db5634b5ebf6bde5c55286239fed2580604132e1473f173e1a1dd4be
MD5
365ba8f6b05b0c780c47462c85792dc6

Observed

Families
RatHat
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
com.node.quick.pure
Main activity
com.node.quick.pure.A1
Internal version
20007
Displayed version
2.0.7
Min SDK
24
Target SDK
34

Permissions (76)

android.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.AUTHENTICATE_ACCOUNTSandroid.permission.BIND_DEVICE_ADMINandroid.permission.CAMERAandroid.permission.CHANGE_WIFI_STATEandroid.permission.DISABLE_KEYGUARDandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_DATA_SYNCandroid.permission.FOREGROUND_SERVICE_MEDIA_PROJECTIONandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.GET_ACCOUNTSandroid.permission.GET_INSTALLED_APPSandroid.permission.INTERNETandroid.permission.KILL_BACKGROUND_PROCESSESandroid.permission.MANAGE_EXTERNAL_STORAGEandroid.permission.MEDIA_PROJECTIONandroid.permission.MODIFY_AUDIO_SETTINGSandroid.permission.POST_NOTIFICATIONSandroid.permission.QUERY_ALL_PACKAGESandroid.permission.QUICKBOOT_POWERONandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_AUDIOandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.READ_MEDIA_VISUAL_USER_SELECTEDandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.READ_SYNC_SETTINGSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.RECORD_AUDIOandroid.permission.REORDER_TASKSandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SCHEDULE_EXACT_ALARMandroid.permission.SYSTEM_ALERT_WINDOWandroid.permission.TURN_SCREEN_ONandroid.permission.USE_BIOMETRICandroid.permission.USE_EXACT_ALARMandroid.permission.USE_FULL_SCREEN_INTENTandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SECURE_SETTINGSandroid.permission.WRITE_SETTINGSandroid.permission.WRITE_SYNC_SETTINGScom.asus.mobilemanager.autostart.permission.ACCESScom.asus.mobilemanager.permission.ACCESScom.coloros.permission.SAFE_COMPONENTcom.google.android.c2dm.permission.RECEIVEcom.google.android.gms.permission.ACTIVITY_RECOGNITIONcom.heytap.permission.SAFE_COMPONENTcom.hihonor.permission.MANAGE_BACKGROUND_ACTIVITYcom.huawei.android.launcher.permission.CHANGE_BADGEcom.huawei.permission.external_app_settings.USE_COMPONENTcom.infinix.permission.BACKGROUND_START_ACTIVITYcom.itel.permission.BACKGROUND_START_ACTIVITYcom.letv.android.permission.BACKGROUND_START_ACTIVITYcom.miui.permission.START_IN_BACKGROUNDcom.motorola.permission.BACKGROUND_START_ACTIVITYcom.node.quick.pure.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONcom.nokia.permission.KEEP_ALIVEcom.realme.permission.SAFE_COMPONENTcom.samsung.android.app.routine.EXECUTEcom.samsung.android.permission.BACKGROUND_START_ACTIVITYcom.samsung.android.permission.MANAGE_ACTIVITY_PROTECTIONcom.samsung.android.sm.permission.KEEP_ALIVEcom.sec.android.provider.badge.permission.READcom.sec.android.provider.badge.permission.WRITEcom.tecno.permission.BACKGROUND_START_ACTIVITYcom.transsion.permission.AUTOSTARTcom.transsion.permission.MANAGE_BACKGROUNDcom.vivo.abe.permission.CLEAN_NOTIFICATIONcom.vivo.permission.manage.permission.ACCESScom.xiaomi.permission.BACKGROUND_START_ACTIVITYoppo.permission.OPPO_COMPONENT_SAFE

Activities (19)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.node.quick.pure.activity.BackgroundTaskActivity
  • com.node.quick.pure.activity.CompatSetupActivity
  • com.node.quick.pure.activity.PackageVerifyActivity
  • com.node.quick.pure.activity.ServiceConfigActivity
  • com.node.quick.pure.activity.TransparentHelperActivity
  • com.node.quick.pure.activity.WelcomeActivity
  • com.node.quick.pure.activity.dpjuxzxd
  • com.node.quick.pure.activity.dyjuyjtaedgx
  • com.node.quick.pure.activity.jlggknlmmvf
  • com.node.quick.pure.activity.nmumfngsucci
  • com.node.quick.pure.activity.ohxyekfez
  • com.node.quick.pure.activity.srbjbsafvch
  • com.node.quick.pure.activity.unhbqhbchvb
  • com.node.quick.pure.erpfkfmymbvq
  • com.node.quick.pure.inject.eaxpofoaehx
  • com.node.quick.pure.service.modules.yw5xud.dgpvxqyd
  • com.node.quick.pure.ui.dgpvxqyd
  • com.node.quick.pure.ui.ghuyzyeob

Services (19)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService
  • com.node.quick.pure.activity.Corepvmzdkweek
  • com.node.quick.pure.keepalive.guard.ubjlhxanr1
  • com.node.quick.pure.keepalive.guard.ubjlhxanr2
  • com.node.quick.pure.service.AppCoreService
  • com.node.quick.pure.service.InitWorkerService
  • com.node.quick.pure.service.MediaDisplayService
  • com.node.quick.pure.service.account.Accountpvmzdkweek
  • com.node.quick.pure.service.account.aaydwede
  • com.node.quick.pure.service.agaehbabxbul
  • com.node.quick.pure.service.bvommhng
  • com.node.quick.pure.service.inyosokjjkx

Receivers (21)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • androidx.work.impl.utils.ForceStopRunnable.BroadcastReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver
  • com.node.quick.pure.receiver.azmgiqch
  • com.node.quick.pure.receiver.nabgzdojak
  • com.node.quick.pure.receiver.wvqavxhl
  • com.node.quick.pure.service.cbnvthpllaks
  • com.node.quick.pure.service.eaebaxvdhn

Providers (4)

  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider
  • com.node.quick.pure.provider.EarlyInitProvider
  • com.node.quick.pure.service.account.StubContentProvider

Intent filters — actions

android.accessibilityservice.AccessibilityServiceandroid.accounts.AccountAuthenticatorandroid.app.action.ACTION_PASSWORD_CHANGEDandroid.app.action.ACTION_PASSWORD_EXPIRINGandroid.app.action.ACTION_PASSWORD_FAILEDandroid.app.action.ACTION_PASSWORD_SUCCEEDEDandroid.app.action.DEVICE_ADMIN_DISABLEDandroid.app.action.DEVICE_ADMIN_DISABLE_REQUESTEDandroid.app.action.DEVICE_ADMIN_ENABLEDandroid.content.SyncAdapterandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.ACTION_SHUTDOWNandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.LOCKED_BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.PACKAGE_ADDEDandroid.intent.action.PACKAGE_CHANGEDandroid.intent.action.PACKAGE_REMOVEDandroid.intent.action.PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.SCREEN_ONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.intent.action.USER_PRESENTandroid.net.conn.CONNECTIVITY_CHANGEandroid.provider.Telephony.SMS_DELIVERandroid.provider.Telephony.SMS_RECEIVEDandroid.service.notification.NotificationListenerServiceandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENTcom.htc.intent.action.QUICKBOOT_POWERONcom.node.quick.pure.action.BACKUP_SYNCcom.node.quick.pure.action.HEALTH_CHECKcom.node.quick.pure.action.QUICK_SYNC

Intent filters — categories

android.intent.category.DEFAULT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
mrcrack65.de5.net/ domain — wss RatHat 2026-10-07

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About RatHat

AI-powered Android credential stealer / RAT (Zimperium, Sep 2026) posing as reward or finance apps (`Tether`, `ReelShort` lures). It serialises the live Accessibility tree to XML and queries Google **Gemini** to resolve on-screen targets and drive synthetic clicks — letting it read and operate banking and wallet apps on the victim's behalf without a human operator. Heavily hardened against analysis: a ~61 MB `AndroidManifest.xml` padded with `0x9999`-byte junk chunks, DEX poisoning (deliberately malformed bytecode that breaks naïve disassemblers), `StringFog`/`StringCrypto` string encryption and ZIP tampering. Configuration lives in a **ZM26 container** under `assets/` — RatHat's own encrypted-blob format: a 4-byte `ZM26` magic, an 8-byte salt, then the payload XOR'd with a repeating 24-byte key (the per-sample `xor_key` from `assets/zm26_meta.json`, concatenated with that salt). The C2 is the `serverUrl` field of `server_config.json` — recoverable in plaintext in some builds, `ZM26`-encrypted in others. The primary FRP tunnel C2 is not a static indicator: it is fetched at runtime by the bundled Go agent `liblocal-service.so`, while `libmedia_codec.so` masquerades as the `frpc` tunnel client.