Flutter SMS Stealer (provisional)

Malware family · 8 sample(s) · 8 indicator record(s) · 8 signing certificate(s) · Active 2026-08-02 → 2026-10-10 (experimental)

About Flutter SMS Stealer (provisional)

A Flutter-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that .so file instead of in the usual Android code.

What it does

  • Harvests SMS messages, contacts, call logs and location and exfiltrates them to the operator.
  • Ships under the stable packages com.dataapp.data_collector and com.jlsw.jmy, as well as randomly-named packages (e.g. com.ncwtaakvv.rzpyvfqstgw).
  • Some builds are additionally wrapped with the Jiagu commercial packer; the Flutter payload is identical once unpacked.

How the C2 is recovered (binary-only)

The command-and-control endpoint is a hardcoded bare-IP HTTP URL compiled directly into the Dart snapshot libapp.so, read out of that file’s string pool. The cluster rotates across a small set of hosting IPs (observed 156.254.21.112, 156.254.21.43, 172.252.173.36, 172.252.224.194, 172.252.224.195, 66.212.58.145). Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
156.254.21.112 ip 0137744ec54f… 2026-10-03
156.254.21.43 ip 35ac16a035e6… 2026-10-08
156.254.21.43 ip ee5c1fe15733… 2026-10-06
172.252.173.36 ip 5a30d9fdfe55… 2026-10-03
172.252.224.194 ip f78e9374f404… 2026-08-02
172.252.224.195 ip d653d39c372a… 2026-09-30
191.124.169.164 ip a7b0a58e6515… 2026-10-10
66.212.58.145 ip c51ff0587c16… 2026-10-01