Nvcgehin Banker Dropper (provisional)

Malware family · 2 sample(s) · 6 indicator record(s) · 2 signing certificate(s) · Active 2026-10-10 (experimental)

About Nvcgehin Banker Dropper (provisional)

Multi-stage Android banking-trojan dropper protected by the bespoke ‘nvcgehin’ packer — a per-build polymorphic, pure-Java crypter (no native library) that nests several AES-256-GCM layers with HKDF-derived keys to conceal and unpack a child banker DEX at runtime. The unpacked banker reports to Firebase Realtime Database instances (observed: alex-538c5, hukum-da57e, demg-5b242, maha-f60b0) and to a Telegram bot (bot token + chat id). C2s were not taken from static config: they were recovered by walking the packer’s decryption chain down to the child payload and confirming the exfil/command sinks that consume them. Provisional bucket pending formal attribution.

Indicators

IndicatorTypeSampleFirst seen
7863871516:aahjwkraboj1yia-h3x8i1ph3k6kj-az2f8 domain 271eba64c973… 2026-10-10
8452452574:aaeq9qvsrb8yx4u70h8ahjwfgrxk8sbiaks@-1003439350135 domain ded45838e957… 2026-10-10
alex-538c5-default-rtdb.firebaseio.com domain ded45838e957… 2026-10-10
demg-5b242-default-rtdb.firebaseio.com domain 271eba64c973… 2026-10-10
hukum-da57e-default-rtdb.asia-southeast1.firebasedatabase.app domain ded45838e957… 2026-10-10
maha-f60b0-default-rtdb.firebaseio.com domain 271eba64c973… 2026-10-10