f720caa316e62abe5b5bc69d…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

UPI OTP Stealer (provisional) — an Android information/credential stealer, distributed as com.twvcudx.heamtn.nqrp, signed with the public Android test/debug key (shared across many unrelated apps, so it is not an author fingerprint). It installs further packages. Communicates with 1 operator endpoint. Indian UPI/card + SMS-OTP banking stealer delivered by a 6-layer ‘guiimmjs’ native dropper (outer com.twvcudx.heamtn.nqrp; final payload bab.tpopeta.uykff, label “Green Gas Limited”). Fully unpacked statically: a native libguiimmjs.so (com.lessiona.surva.Crypto) AES-256-GCM / HKDF-SHA256-decrypts assets/tdyfltfejge -> a stage-1 DEX that reassembles 10 fake-PNG chunks (assets/kvfp/wruq_0..9.png), XORs them with SHA256(key), AES-256-CBC-decrypts and gunzips -> the payload APK, whose Sjyvsafs packer XOR+gunzips assets/4f7eceb3 and in-memory-loads the real 6.2 MB stealer DEX. All C2 indicators binary-verified from the final DEX.

Communication. Retrofit/OkHttp over HTTPS (JSON), certificate-pinned, to https://deploy229.cehtech.net. Commands are delivered by Firebase Cloud Messaging push (fetch_old_sms, fetch_contacts, read-contacts, send-sms, forwarding-sim-update, CMD_SYNC, CMD_RST/CMD_RST_FULL); the device registers its FCM token and sends lastSeen heartbeats. Endpoints (relative to the C2 host):

  • Registration / liveness: api/devices/{deviceId}, api/devices/{deviceId}/fcm-token, api/devices/{deviceId}/lastSeen, api/devices/{deviceId}/simInfo, .../simSlots/{slot}
  • Exfiltration (JSON batches): api/devices/{id}/sms and devices/{deviceId}/sms-sent (incoming SMS/OTP and send confirmations), api/devices/{uniqueid}/contacts/batch (contacts), api/devices/{uniqueid}/notifications/batch (notifications), and api/card_payments, api/net_banking, api/form_submissions, api/success_data (UPI / card / net-banking credentials captured by the fake bank activities); api/crashes for telemetry
  • OTP hijack: api/admin/globalPhone, api/devices/{id}/adminPhone, api/devices/{id}/admins push operator phone numbers to which intercepted OTP SMS are re-sent via sendTextMessage; api/devices/{id}/forwardingSim with devices/{deviceId}/ussd-result and devices/{deviceId}/call-forward-result run USSD codes to set call forwarding to an attacker SIM, routing voice/voice-OTP to the operator.

India-targeted (Hinglish strings in the stealer, e.g. “SIM inserted nahi hai”). Indicators: https://deploy229.cehtech.net.

Recovered configuration

package
com.twvcudx.heamtn.nqrp

Identification

SHA-256
f720caa316e62abe5b5bc69d89b76e7b704b82355e23847bd1439f2edc50af89
MD5
cab9f7ac767de47c84483c3cee53e576

Observed

Families
UPI OTP Stealer (provisional)
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
com.twvcudx.heamtn.nqrp
Main activity
com.twvcudx.heamtn.nqrp.CwonJuzks
Internal version
1
Displayed version
1.0
Min SDK
24
Target SDK
35

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (7)

android.permission.ACCESS_NETWORK_STATEandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.REQUEST_INSTALL_PACKAGEScom.twvcudx.heamtn.nqrp.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.twvcudx.heamtn.nqrp.CwonJuzks
  • com.twvcudx.heamtn.nqrp.KHRybunkg

Services (2)

  • com.twvcudx.heamtn.nqrp.BOMDyZJja
  • com.twvcudx.heamtn.nqrp.PATqOsNxi

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • com.twvcudx.heamtn.nqrp.CRbXZIZSi

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters — actions

android.net.VpnServiceandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
deploy229.cehtech.net domain — https UPI OTP Stealer (provisional) 2026-10-07

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.