Shellapp WebView Exfil (provisional)

Malware family · 6 sample(s) · 6 indicator record(s) · 0 signing certificate(s) · Active 2026-09-06 → 2026-10-11 (experimental)

About Shellapp WebView Exfil (provisional)

Shellapp WebView Exfil (provisional) is the WebView-beacon payload shipped by the multi-stage “shellapp” native dropper (same packer as Shellapp VNC RAT and Telegram Phish Proxy; see the shellapp-packer note). The final stage loads https://{domain}/webview/photo?buildVersion=<tag> in a JavaScript-enabled WebView via WebView.loadUrl for photo/data exfil; the C2 domain is leaf-decoded (base64 + per-byte XOR, per-build keys) from a domain-list carrier class and substituted into the template. Per build the outer package, loader/class names, native lib name, asset paths and per-stage keys are re-randomized. C2s recovered statically by source-to-sink for 6 samples (e.g. mwdnawdnnawdnawdn.top, sentabr18djfos.top, fdsfgdsgsf3.icu, susisosndh1.icu, fhsk0909cd.sbs, babeloevkabosskita15.lol). Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
babeloevkabosskita15.lol/webview/photo domain 7c77da3f0300… 2026-09-26
fdsfgdsgsf3.icu/webview/photo domain c67086b3adbc… 2026-09-06
fhsk0909cd.sbs/webview/photo domain 9011a4b1cf4a… 2026-09-09
mwdnawdnnawdnawdn.top/webview/photo domain aae8a77820bc… 2026-10-11
sentabr18djfos.top/webview/photo domain ed7f2f37a766… 2026-09-20
susisosndh1.icu/webview/photo domain c15c162c47d0… 2026-09-06