SMS Forwarder (provisional)

Malware family · 7 sample(s) · 10 indicator record(s) · 2 signing certificate(s) · Active 2026-08-17 → 2026-10-05 (experimental)

About SMS Forwarder (provisional)

A broad class of simple Android OTP/SMS stealers (packages like com.example.smsforwarder) that register a RECEIVE_SMS receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only:

  • Telegram bot - the message is sent through the Telegram Bot API; the bot token(s) (<id>:<authstring>) and target chat_id are hardcoded, so api.telegram.org is the C2 and the bot token is the actionable IOC (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback).
  • HTTP drop - the message is POSTed to a hardcoded endpoint, typically a bare IP with an /sms / ingest PHP handler.

Family label is provisional - these are commodity builders, not a single actor.

Indicators

IndicatorTypeSampleFirst seen
api.telegram.org domain 3dbbc7a01101… 2026-09-20
api.telegram.org domain 0050e3ef2812… 2026-09-03
api.telegram.org domain a23457417014… 2026-09-30
api.telegram.org domain c25f721eba1d… 2026-08-17
api.telegram.org domain 9354d54a1c6b… 2026-08-17
api.telegram.org domain e9f1b821f204… 2026-10-05
vip-panel-krish-developer.42web.io/ domain 3dbbc7a01101… 2026-09-20
vip-panel-krish-developer.42web.io/ domain c25f721eba1d… 2026-08-17
vip-panel-krish-developer.42web.io/ domain 9354d54a1c6b… 2026-08-17
158.247.219.34/sms/sms_ingest.php ip b920ac40a219… 2026-09-27