WebSocket VNC Banker (provisional)

Malware family · 22 sample(s) · 48 indicator record(s) · 3 signing certificate(s) · Active 2026-09-22 → 2026-10-09 (experimental)

About WebSocket VNC Banker (provisional)

WebSocket VNC Banker (provisional) is an Android overlay/VNC banking trojan that talks to its operator over a WebSocket channel. The C2 endpoint is ws://:8080/, where the host is held as an AES-128-CBC-encrypted, base64-encoded field decrypted at runtime with a PBKDF2-HMAC-SHA1 key (password, salt, 65536 iterations, 128-bit) and a string IV, then DNS-resolved before connecting (after an HTTP reachability probe). It injects overlays for credential theft, intercepts SMS and one-time passwords, pins a custom CA, and sends device headers (X-Device-Id, X-Device-Model, X-Api-Level). Strings are hidden behind a byte-array XOR decoder plus opaque-predicate (hashCode sparse-switch) control-flow obfuscation and a fill-array-data element-width-17 trap that breaks jadx/baksmali/androguard, so the C2 is recovered by running the sample decoders on a JVM. Seen both as a standalone app and as the payload of a Brazilian Correios-lure dropper (child package dune.firefly.imagine). Observed C2s include 107.148.78.150:8080 and 190.2.184.130:8080. Family label provisional.

Indicators

IndicatorTypeSampleFirst seen
adminbtmob.devseven.lat:5000/l/daycoval domain de9067854fac… 2026-10-02
107.148.78.150:8080/ ip 35fa397fa0ab… 2026-10-05
151.243.218.249:8080/ ip c1a744053b16… 2026-10-03
151.243.218.93:8080/ ip 4935988e625e… 2026-10-08
151.243.218.96:8080/ ip 974cd615c3c8… 2026-10-05
151.243.218.96:8080/ ip 6cf139ac118a… 2026-09-30
162.35.114.77:8080/ ip b9116a727822… 2026-10-06
162.35.114.77:8080/ ip e30bb45f3061… 2026-10-07
167.148.193.58:8080/ ip ad505a9f9454… 2026-10-08
167.86.110.102:8080/ ip 307716b78bf3… 2026-10-06
167.86.110.102:8080/ ip 4afee3039ddd… 2026-10-09
179.0.176.65:8080/ ip de9067854fac… 2026-10-02
179.0.176.65:8080/ ip df944a1b245b… 2026-09-25
190.102.41.210:5000 ip 4935988e625e… 2026-10-08
190.102.41.210:5000 ip 974cd615c3c8… 2026-10-05
190.102.41.210:5000 ip b9116a727822… 2026-10-06
190.102.41.210:5000 ip ca9dfedcf27c… 2026-10-06
190.102.41.210:5000 ip e0d08831bf20… 2026-10-06
190.102.41.210:5000 ip e30bb45f3061… 2026-10-07
190.102.41.210:5000 ip ead8e697c9bb… 2026-09-22
190.102.41.210:5000 ip 144101b61343… 2026-10-01
190.102.41.210:5000 ip 63aee9e11fc9… 2026-09-26
190.102.41.210:5000 ip 9a0beecf77d8… 2026-10-06
190.102.41.210:5000 ip c1a744053b16… 2026-10-03
190.102.41.210:5000 ip de9067854fac… 2026-10-02
190.102.41.210:5000 ip 307716b78bf3… 2026-10-06
190.102.41.210:5000 ip 6cf139ac118a… 2026-09-30
190.102.41.210:5000 ip ad505a9f9454… 2026-10-08
190.102.41.210:5000 ip ca628eca7567… 2026-10-08
190.102.41.210:5000 ip df944a1b245b… 2026-09-25
190.102.41.210:5000 ip 944b82cc545d… 2026-09-23
190.102.42.119:8080/ ip 9a0beecf77d8… 2026-10-06
190.2.184.130:8080/ ip 50300b6973d5… 2026-10-09
191.96.224.178:8080/ ip ca9dfedcf27c… 2026-10-06
191.96.225.176:8080/ ip e0d08831bf20… 2026-10-06
191.96.225.176:8080/ ip 144101b61343… 2026-10-01
191.96.78.64:8080/ ip d45e654d66c4… 2026-10-01
191.96.79.100:5000 ip 4afee3039ddd… 2026-10-09
207.180.3.224:8080/ ip 4935988e625e… 2026-10-08
212.38.89.110:8080/ ip 4935988e625e… 2026-10-08
212.69.5.117:8080/ ip 4935988e625e… 2026-10-08
212.69.5.14:8080/ ip 974cd615c3c8… 2026-10-05
212.69.5.14:8080/ ip 6cf139ac118a… 2026-09-30
212.69.5.83:8080/ ip ca628eca7567… 2026-10-08
37.148.135.17:8080/ ip ead8e697c9bb… 2026-09-22
45.158.8.241:8080/ ip 63aee9e11fc9… 2026-09-26
45.158.8.241:8080/ ip 944b82cc545d… 2026-09-23
45.158.8.48:8080/ ip 944b82cc545d… 2026-09-23

Operators / owners (9)

Operator handles recovered from sample configuration (for example the owner_username baked into the C2 panel). Click to list that operator's indicators.

Detected samples without extractable endpoint (1)

Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
ba1a7149f21b6ad992f768881cab2571659dd75f289f17f1f9a7961495f70461 com.cmxwxuio.wqbajz Brazilian WebView install-front DROPPER (loader package com.cmxwxuio.wqbajz) of the WebSocket VNC Banker family (assets/hzpjbk.dat LCG payload, skip 16 + seed 894016548, and the /yaarsa/private/ probe-path marker). This build's server_config.json panel is empty and the embedded banker is wrapped in a native-code packer (ProxyApplication/JniBridge loader with an encrypted lib*.so), so the banker C2 is not statically recoverable - needs a dynamic run. Recorded as a detection. source 2026-09-30