HK Banking Stealer (provisional)
Malware family · 1 sample(s) · 1 indicator record(s) · 1 signing certificate(s) · Active 2026-10-08 (experimental)
About HK Banking Stealer (provisional)
Packed Android banking/crypto-wallet stealer aimed at Hong Kong and mainland-China victims. Ships a three-layer payload: an AES-CBC-encrypted cfg.dat (key sK8xQ2mN7vL4pR9w) yields the config, which unlocks an AES-encrypted data.bin second stage; in-code strings are stored as ENC: blobs XOR-decrypted with a fixed key. The recovered stage exfiltrates banking and cryptocurrency-wallet data over a raw TCP socket to its C2 at 114.66.37.132. Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 114.66.37.132 | ip | d27a9bf383b5… | 2026-10-08 |