GosuVPN Dropper (provisional)
Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s) · Active 2026-10-08 (experimental)
About GosuVPN Dropper (provisional)
GosuVPN Dropper (provisional) is an Android install-time dropper (package
com.sbyvt.qodevfkr; REQUEST_INSTALL_PACKAGES, QUERY_ALL_PACKAGES, RECEIVE_BOOT_COMPLETED) hidden behind a “gosuvpn” VPN lure. The real child payload ships as an encrypted ~4.4 MB asset (assets/jcvwjmntop.bin, marker .__wombat_payload__.) and is installed as genome.apk/g.apk; the install UI is assets/bloom.html with a {{BLOOM_DOWNLOADS}} template and decoy store links. Dropper strings are obfuscated with StringFog (com.github.megatronking.stringfog.xor, repeating-key XOR); decoding the StringFog byte-array pairs recovers the distribution/C2 host https://gosuvpnweb.top. The sample also embeds a spoofed OnePlus 8 Pro build fingerprint and many decoy padding assets. C2 recovered statically via source-to-sink StringFog decode; family label provisional.Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| gosuvpnweb.top | domain | e3832322e716… | 2026-10-08 |