Supply-chain & runtime detections
Samples whose decoder matched a known family but carry no extractable network indicator — backdoors that receive their C2 at runtime (via push, staging server, or hard-coded loader). Detection here is by code marker, not by endpoint.
| SHA-256 | Family | Package | Decoder note | First seen |
|---|---|---|---|---|
| 0713ff7bb8d9… | APT-C-27 | com.sysoff.uucryptoseven.hmza | — | |
| 8f997e606a13… | SyrianMT | GOOD.BYE.GOOGLE | 2020-04-13 | |
| 55e8b2d87f80… | DCHSpy | hazrateeshgh.apk | Flutter-built "Hazrate Eshgh" (حضرت عشق) gallery app themed on Mahsa (Jina) Amini - a political lure matching DCHSpy's Telegram distribution to Farsi speakers. SHA-1 listed in Lookout's DCHSpy IoCs; no endpoint is statically extractable from the Flutter build (config fetched at runtime), so this is a code-/hash-level attribution. analysis | 2024-04-13 |
About APT-C-27
Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.
About DCHSpy
Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.
About SyrianMT
Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".