Flutter Banking Overlay (provisional)
Malware family · 3 sample(s) · 5 indicator record(s) · 1 signing certificate(s) · Active 2026-08-26 → 2026-10-06 (experimental)
About Flutter Banking Overlay (provisional)
A Flutter-built Android banking trojan distributed as a betting/casino app (observed package com.apkhadesbet, a “hadesbet” gambling lure). Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so instead of to normal Java/DEX code, so both the behaviour and the C2 live in that .so file rather than in the usual Android code.
What it does
- Bundles a second payload APK (
assets/bound_payload.apk) that it installs/loads. - Uses
flutter_inappwebview(an embedded browser) to pop fake bank-login overlays on top of real apps and harvest credentials. Observed targeting Canadian institutions - RBC (royalbank.com), BMO (bmodigitalbanking.com), CIBC, Desjardins, Domino - plus the MuchBetter wallet (muchbetter.com), behind gambling lures (hadesbet3.com,betonredcasinobe.com).
How the C2 is recovered (binary-only)
The operator backend is a single hardcoded HTTPS base URL compiled into the Dart snapshot libapp.so, read directly from that file’s string pool. It sits on a throwaway PaaS host (a *.ondigitalocean.app subdomain) and is deliberately kept separate from (a) the overlay-target bank domains the trojan phishes and (b) the attribution SDKs it ships (AppsFlyer / OneLink); the decoder filters those out so only the real operator backend is recorded. Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| data.ncup.team | domain | 06a47ef466f1… | 2026-08-26 |
| data.ncup.team | domain | c7b6c2ea5a80… | 2026-09-07 |
| n1cdatadev-nrfru.ondigitalocean.app | domain | 65fc2a875abb… | 2026-10-06 |
| n1cdatadev-nrfru.ondigitalocean.app | domain | 06a47ef466f1… | 2026-08-26 |
| n1cdatadev-nrfru.ondigitalocean.app | domain | c7b6c2ea5a80… | 2026-09-07 |