WebSocket VNC Banker (provisional)
Malware family · 22 sample(s) · 48 indicator record(s) · 3 signing certificate(s) · Active 2026-09-22 → 2026-10-09 (experimental)
About WebSocket VNC Banker (provisional)
WebSocket VNC Banker (provisional) is an Android overlay/VNC banking trojan that talks to its operator over a WebSocket channel. The C2 endpoint is ws://:8080/, where the host is held as an AES-128-CBC-encrypted, base64-encoded field decrypted at runtime with a PBKDF2-HMAC-SHA1 key (password, salt, 65536 iterations, 128-bit) and a string IV, then DNS-resolved before connecting (after an HTTP reachability probe). It injects overlays for credential theft, intercepts SMS and one-time passwords, pins a custom CA, and sends device headers (X-Device-Id, X-Device-Model, X-Api-Level). Strings are hidden behind a byte-array XOR decoder plus opaque-predicate (hashCode sparse-switch) control-flow obfuscation and a fill-array-data element-width-17 trap that breaks jadx/baksmali/androguard, so the C2 is recovered by running the sample decoders on a JVM. Seen both as a standalone app and as the payload of a Brazilian Correios-lure dropper (child package dune.firefly.imagine). Observed C2s include 107.148.78.150:8080 and 190.2.184.130:8080. Family label provisional.
Indicators
Operators / owners (9)
Operator handles recovered from sample configuration (for example the owner_username baked into the C2 panel). Click to list that operator's indicators.
Detected samples without extractable endpoint (1)
Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| ba1a7149f21b6ad992f768881cab2571659dd75f289f17f1f9a7961495f70461 | com.cmxwxuio.wqbajz | Brazilian WebView install-front DROPPER (loader package com.cmxwxuio.wqbajz) of the WebSocket VNC Banker family (assets/hzpjbk.dat LCG payload, skip 16 + seed 894016548, and the /yaarsa/private/ probe-path marker). This build's server_config.json panel is empty and the embedded banker is wrapped in a native-code packer (ProxyApplication/JniBridge loader with an encrypted lib*.so), so the banker C2 is not statically recoverable - needs a dynamic run. Recorded as a detection. source | 2026-09-30 |