Black Hawk
Malware family · 12 sample(s) · 14 indicator record(s) · 2 signing certificate(s) · Active 2026-09-20 → 2026-10-08 (experimental)
About Black Hawk
An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a “Rakuten account protection” app (label “楽天アカウント保護”, padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family’s extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| echo.mmaldwh.com | domain | eaaaf4000ff4… | 2026-09-20 |
| tnt.freedomdf.xyz | domain | 12b72de4d786… | 2026-10-08 |
| tnt.freedomdf.xyz | domain | 6827edb54e23… | 2026-10-07 |
| v-game.eu.cc/full.html | domain | 8c08e15adf3e… | 2026-09-20 |
| www.collectpointsjp.com | domain | 429c9de426ae… | 2026-10-05 |
| www.collectpointsjp.com | domain | 80656cdb810b… | 2026-10-03 |
| www.collectpointsjp.com | domain | 1ac8f4d8af26… | 2026-10-02 |
| www.collectpointsjp.com | domain | c84508ae0813… | 2026-10-01 |
| www.heiyingnb.xyz | domain | b49d3191d491… | 2026-09-30 |
| www.hyzj.shop | domain | 2b2de48e0f4e… | 2026-09-30 |
| www.hyzj.shop | domain | eaaaf4000ff4… | 2026-09-20 |
| www.mangcun.xyz | domain | d6a014c7f963… | 2026-09-30 |
| www.mangcun.xyz | domain | 8c08e15adf3e… | 2026-09-20 |
| 193.32.2.245:8080/ws/device | ip | 322b70d95c18… | 2026-09-29 |