Flutter Banking Overlay (provisional)

Malware family · 3 sample(s) · 5 indicator record(s) · 1 signing certificate(s) · Active 2026-08-26 → 2026-10-06 (experimental)

About Flutter Banking Overlay (provisional)

A Flutter-built Android banking trojan distributed as a betting/casino app (observed package com.apkhadesbet, a “hadesbet” gambling lure). Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so instead of to normal Java/DEX code, so both the behaviour and the C2 live in that .so file rather than in the usual Android code.

What it does

  • Bundles a second payload APK (assets/bound_payload.apk) that it installs/loads.
  • Uses flutter_inappwebview (an embedded browser) to pop fake bank-login overlays on top of real apps and harvest credentials. Observed targeting Canadian institutions - RBC (royalbank.com), BMO (bmodigitalbanking.com), CIBC, Desjardins, Domino - plus the MuchBetter wallet (muchbetter.com), behind gambling lures (hadesbet3.com, betonredcasinobe.com).

How the C2 is recovered (binary-only)

The operator backend is a single hardcoded HTTPS base URL compiled into the Dart snapshot libapp.so, read directly from that file’s string pool. It sits on a throwaway PaaS host (a *.ondigitalocean.app subdomain) and is deliberately kept separate from (a) the overlay-target bank domains the trojan phishes and (b) the attribution SDKs it ships (AppsFlyer / OneLink); the decoder filters those out so only the real operator backend is recorded. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
data.ncup.team domain 06a47ef466f1… 2026-08-26
data.ncup.team domain c7b6c2ea5a80… 2026-09-07
n1cdatadev-nrfru.ondigitalocean.app domain 65fc2a875abb… 2026-10-06
n1cdatadev-nrfru.ondigitalocean.app domain 06a47ef466f1… 2026-08-26
n1cdatadev-nrfru.ondigitalocean.app domain c7b6c2ea5a80… 2026-09-07