SecretShoot Crypto Drainer (provisional)

Malware family · 14 sample(s) · 14 indicator record(s) · 13 signing certificate(s) · Active 2026-07-25 → 2026-10-09 (experimental)

About SecretShoot Crypto Drainer (provisional)

Chinese accessibility-driven crypto-wallet drainer disguised as an adult-video app (秘色视频). An AccessibilityService automates on-device crypto withdrawals against targeted wallet/exchange apps (Gate.io, Trust Wallet, imToken) and PhonePe, reading and filling fund-password, amount and SMS/email 2FA fields and tapping confirm, while a WebView JS bridge and a WebSocket channel talk to the operator. Strings are per-string XOR-obfuscated; the build layers decoy services, staged .bt assets and ad-SDK noise. C2 is a wss:// command channel plus an HTTPS error-reporting endpoint on the same operator domain, recovered by decoding the obfuscated config. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
giwyeje.top/api/ws/ domain 9b12eaf52eae… 2026-08-14
gskdjw.top/api/ws/ domain 11a510e9d92b… 2026-08-25
gskdjw.top/api/ws/ domain 2de1f27b63c3… 2026-08-25
hjwgebe.top/api/ws/ domain 38116589741a… 2026-08-28
hjwsvdb.skin/api/ws/ domain cafd4c58b4e5… 2026-10-09
hjwsvdb.skin/api/ws/ domain 2ad09d4b8d5a… 2026-09-09
hjwsvdb.skin/api/ws/ domain 47cead414728… 2026-10-02
hjwsvdb.skin/api/ws/ domain 86fb6d6ad7dd… 2026-09-14
hjwsvdb.skin/api/ws/ domain 9ac5ce723b6c… 2026-10-09
hjwsvdb.skin/api/ws/ domain f888165c7bf0… 2026-09-08
yiwdjbd.top/api/ws/ domain b15959a07d3e… 2026-09-23
yiwdjbd.top/api/ws/ domain 315499d49ce1… 2026-07-25
yiwdjbd.top/api/ws/ domain bd898993d274… 2026-08-05
192.168.8.175:3000/api/ws/ ip ac20f08c0cc3… 2026-09-24