Flutter SMS Stealer (provisional)
Malware family · 8 sample(s) · 8 indicator record(s) · 8 signing certificate(s) · Active 2026-08-02 → 2026-10-10 (experimental)
About Flutter SMS Stealer (provisional)
A Flutter-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that .so file instead of in the usual Android code.
What it does
- Harvests SMS messages, contacts, call logs and location and exfiltrates them to the operator.
- Ships under the stable packages
com.dataapp.data_collectorandcom.jlsw.jmy, as well as randomly-named packages (e.g.com.ncwtaakvv.rzpyvfqstgw). - Some builds are additionally wrapped with the Jiagu commercial packer; the Flutter payload is identical once unpacked.
How the C2 is recovered (binary-only)
The command-and-control endpoint is a hardcoded bare-IP HTTP URL compiled directly into the Dart snapshot libapp.so, read out of that file’s string pool. The cluster rotates across a small set of hosting IPs (observed 156.254.21.112, 156.254.21.43, 172.252.173.36, 172.252.224.194, 172.252.224.195, 66.212.58.145). Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 156.254.21.112 | ip | 0137744ec54f… | 2026-10-03 |
| 156.254.21.43 | ip | 35ac16a035e6… | 2026-10-08 |
| 156.254.21.43 | ip | ee5c1fe15733… | 2026-10-06 |
| 172.252.173.36 | ip | 5a30d9fdfe55… | 2026-10-03 |
| 172.252.224.194 | ip | f78e9374f404… | 2026-08-02 |
| 172.252.224.195 | ip | d653d39c372a… | 2026-09-30 |
| 191.124.169.164 | ip | a7b0a58e6515… | 2026-10-10 |
| 66.212.58.145 | ip | c51ff0587c16… | 2026-10-01 |