Black Hawk

Malware family · 12 sample(s) · 14 indicator record(s) · 2 signing certificate(s) · Active 2026-09-20 → 2026-10-08 (experimental)

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a “Rakuten account protection” app (label “楽天アカウント保護”, padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family’s extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.

Indicators

IndicatorTypeSampleFirst seen
echo.mmaldwh.com domain eaaaf4000ff4… 2026-09-20
tnt.freedomdf.xyz domain 12b72de4d786… 2026-10-08
tnt.freedomdf.xyz domain 6827edb54e23… 2026-10-07
v-game.eu.cc/full.html domain 8c08e15adf3e… 2026-09-20
www.collectpointsjp.com domain 429c9de426ae… 2026-10-05
www.collectpointsjp.com domain 80656cdb810b… 2026-10-03
www.collectpointsjp.com domain 1ac8f4d8af26… 2026-10-02
www.collectpointsjp.com domain c84508ae0813… 2026-10-01
www.heiyingnb.xyz domain b49d3191d491… 2026-09-30
www.hyzj.shop domain 2b2de48e0f4e… 2026-09-30
www.hyzj.shop domain eaaaf4000ff4… 2026-09-20
www.mangcun.xyz domain d6a014c7f963… 2026-09-30
www.mangcun.xyz domain 8c08e15adf3e… 2026-09-20
193.32.2.245:8080/ws/device ip 322b70d95c18… 2026-09-29