f720caa316e62abe5b5bc69d…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
UPI OTP Stealer (provisional) — an Android information/credential stealer, distributed as com.twvcudx.heamtn.nqrp, signed with the public Android test/debug key (shared across many unrelated apps, so it is not an author fingerprint). It installs further packages. Communicates with 1 operator endpoint. Indian UPI/card + SMS-OTP banking stealer delivered by a 6-layer ‘guiimmjs’ native dropper (outer com.twvcudx.heamtn.nqrp; final payload bab.tpopeta.uykff, label “Green Gas Limited”). Fully unpacked statically: a native libguiimmjs.so (com.lessiona.surva.Crypto) AES-256-GCM / HKDF-SHA256-decrypts assets/tdyfltfejge -> a stage-1 DEX that reassembles 10 fake-PNG chunks (assets/kvfp/wruq_0..9.png), XORs them with SHA256(key), AES-256-CBC-decrypts and gunzips -> the payload APK, whose Sjyvsafs packer XOR+gunzips assets/4f7eceb3 and in-memory-loads the real 6.2 MB stealer DEX. All C2 indicators binary-verified from the final DEX.
Communication. Retrofit/OkHttp over HTTPS (JSON), certificate-pinned, to https://deploy229.cehtech.net. Commands are delivered by Firebase Cloud Messaging push (fetch_old_sms, fetch_contacts, read-contacts, send-sms, forwarding-sim-update, CMD_SYNC, CMD_RST/CMD_RST_FULL); the device registers its FCM token and sends lastSeen heartbeats. Endpoints (relative to the C2 host):
- Registration / liveness:
api/devices/{deviceId},api/devices/{deviceId}/fcm-token,api/devices/{deviceId}/lastSeen,api/devices/{deviceId}/simInfo,.../simSlots/{slot} - Exfiltration (JSON batches):
api/devices/{id}/smsanddevices/{deviceId}/sms-sent(incoming SMS/OTP and send confirmations),api/devices/{uniqueid}/contacts/batch(contacts),api/devices/{uniqueid}/notifications/batch(notifications), andapi/card_payments,api/net_banking,api/form_submissions,api/success_data(UPI / card / net-banking credentials captured by the fake bank activities);api/crashesfor telemetry - OTP hijack:
api/admin/globalPhone,api/devices/{id}/adminPhone,api/devices/{id}/adminspush operator phone numbers to which intercepted OTP SMS are re-sent viasendTextMessage;api/devices/{id}/forwardingSimwithdevices/{deviceId}/ussd-resultanddevices/{deviceId}/call-forward-resultrun USSD codes to set call forwarding to an attacker SIM, routing voice/voice-OTP to the operator.
India-targeted (Hinglish strings in the stealer, e.g. “SIM inserted nahi hai”). Indicators: https://deploy229.cehtech.net.
Recovered configuration
Identification
- SHA-256
- f720caa316e62abe5b5bc69d89b76e7b704b82355e23847bd1439f2edc50af89
- MD5
- cab9f7ac767de47c84483c3cee53e576
Observed
- Families
- UPI OTP Stealer (provisional)
- First seen
- 2026-10-07
APK metadata
Summary
- Type
- Android · APK
- Package
- com.twvcudx.heamtn.nqrp
- Main activity
- com.twvcudx.heamtn.nqrp.CwonJuzks
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 24
- Target SDK
- 35
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
- Subject email
- android@android.com
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Permissions (7)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| deploy229.cehtech.net | domain | — | https | UPI OTP Stealer (provisional) | 2026-10-07 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.