Nvcgehin Banker Dropper (provisional)
Malware family · 2 sample(s) · 6 indicator record(s) · 2 signing certificate(s) · Active 2026-10-10 (experimental)
About Nvcgehin Banker Dropper (provisional)
Multi-stage Android banking-trojan dropper protected by the bespoke ‘nvcgehin’ packer — a per-build polymorphic, pure-Java crypter (no native library) that nests several AES-256-GCM layers with HKDF-derived keys to conceal and unpack a child banker DEX at runtime. The unpacked banker reports to Firebase Realtime Database instances (observed: alex-538c5, hukum-da57e, demg-5b242, maha-f60b0) and to a Telegram bot (bot token + chat id). C2s were not taken from static config: they were recovered by walking the packer’s decryption chain down to the child payload and confirming the exfil/command sinks that consume them. Provisional bucket pending formal attribution.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 7863871516:aahjwkraboj1yia-h3x8i1ph3k6kj-az2f8 | domain | 271eba64c973… | 2026-10-10 |
| 8452452574:aaeq9qvsrb8yx4u70h8ahjwfgrxk8sbiaks@-1003439350135 | domain | ded45838e957… | 2026-10-10 |
| alex-538c5-default-rtdb.firebaseio.com | domain | ded45838e957… | 2026-10-10 |
| demg-5b242-default-rtdb.firebaseio.com | domain | 271eba64c973… | 2026-10-10 |
| hukum-da57e-default-rtdb.asia-southeast1.firebasedatabase.app | domain | ded45838e957… | 2026-10-10 |
| maha-f60b0-default-rtdb.firebaseio.com | domain | 271eba64c973… | 2026-10-10 |