Supply-chain & runtime detections

Samples whose decoder matched a known family but carry no extractable network indicator — backdoors that receive their C2 at runtime (via push, staging server, or hard-coded loader). Detection here is by code marker, not by endpoint.

SHA-256FamilyPackageDecoder noteFirst seen
0713ff7bb8d9… APT-C-27 com.sysoff.uucryptoseven.hmza —
8f997e606a13… SyrianMT GOOD.BYE.GOOGLE 2020-04-13
55e8b2d87f80… DCHSpy hazrateeshgh.apk Flutter-built "Hazrate Eshgh" (حضرت عشق) gallery app themed on Mahsa (Jina) Amini - a political lure matching DCHSpy's Telegram distribution to Farsi speakers. SHA-1 listed in Lookout's DCHSpy IoCs; no endpoint is statically extractable from the Flutter build (config fetched at runtime), so this is a code-/hash-level attribution. analysis 2024-04-13

About APT-C-27

Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.

About DCHSpy

Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.

About SyrianMT

Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".