d27a9bf383b5a969d61206fa…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

HK Banking Stealer (provisional) — an Android banking trojan, distributed as ptonk.lv3c3.rkmmg, self-signed as “ba6152c2”. It installs further packages. Communicates with 1 operator endpoint. Three-stage packed Android banking/crypto stealer disguised as a system/Google Play update (app label “系统更新”, “发现新版本” update dialog). Stage 1 (package ptonk.lv3c3.rkmmg, loader com.forest481.security) AES-CBC-decrypts assets/cfg.dat with the hardcoded key “sK8xQ2mN7vL4pR9w” to a properties config (target package app.topsafe871, rk = base64 AES key for the payload), then AES-CBC-decrypts assets/data.bin with that key to a stage-2 APK (app.topsafe871). The stage-2 dex string-encrypts every literal as ENC: blobs, deobfuscated by com.forest481.security.util.CryptoUtil.decrypt = base64-decode then repeating-XOR with “x9#Kp$2mL@7vQ!nZ”. Decrypting those recovers the C2 (raw TCP socket to 114.66.37.132, port from server_port config) and the target-app list: HK/China banking and crypto-wallet apps including HSBC HK (hk.com.hsbc.hsbchkmobilebanking), Bank of China HK (com.bochk.app.aos), SPDB (cn.com.spdb.mobilebank.per), Binance, imToken (im.token.app) and TokenPocket (vip.mytokenpocket). C2 binary-verified by full static unpack of all three stages. Family label provisional. Indicators: 114.66.37.132.

Recovered configuration

c2_transport
raw TCP socket (server_port config)
lure
Google Play / system update (Chinese)
package
ptonk.lv3c3.rkmmg
packer
3-stage AES (cfg.dat/data.bin) + ENC: XOR string crypto
stage2_package
app.topsafe871
targets
HK/China banking + crypto wallets (HSBC HK, BOCHK, SPDB, Binance, imToken, TokenPocket)

Identification

SHA-256
d27a9bf383b5a969d61206fa16a6734477d0c5bb93740b6aebb3049446ed42ce
MD5
1dbc5aff5faf8ed015aef54952ea09ff

Observed

Families
HK Banking Stealer (provisional)
First seen
2026-10-08

APK metadata

Summary

Type
Android · APK
Package
ptonk.lv3c3.rkmmg
Main activity
com.forest481.security.MainActivity
Internal version
1
Displayed version
1.0
Min SDK
21
Target SDK
34

Signing certificate

Valid from
2026-04-10 12:51:22
Valid to
2126-03-17 12:51:22
Serial
5f469d13
Thumbprint
542a739db417f9680bc246819872e75f16b5ba40
Subject
C:ba6152c2, CN:ba6152c2, L:ba6152c2, O:ba6152c2, ST:ba6152c2, OU:ba6152c2
Issuer
C:ba6152c2, CN:ba6152c2, L:ba6152c2, O:ba6152c2, ST:ba6152c2, OU:ba6152c2

Permissions (4)

android.permission.ACCESS_NETWORK_STATEandroid.permission.INTERNETandroid.permission.REQUEST_INSTALL_PACKAGESptonk.lv3c3.rkmmg.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (1)

  • com.forest481.security.MainActivity

Receivers (1)

  • androidx.profileinstaller.ProfileInstallReceiver

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters — actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
114.66.37.132 ip — — HK Banking Stealer (provisional) 2026-10-08

Signing certificate

Subject CN
ba6152c2
Issuer CN
ba6152c2
Fingerprint
83c9cec90600c6e764289f294dfb33d476b69bab5ff3fb03826ba3fb69367ad9

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.