5a30d9fdfe55eb6e1c52568a…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Flutter SMS Stealer (provisional). A Flutter-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that .so file instead of in the usual Android code.

What it does

  • Harvests SMS messages, contacts, call logs and location and exfiltrates them to the operator.
  • Ships under the stable packages com.dataapp.data_collector and com.jlsw.jmy, as well as randomly-named packages (e.g. com.ncwtaakvv.rzpyvfqstgw).
  • Some builds are additionally wrapped with the Jiagu commercial packer; the Flutter payload is identical once unpacked.

How the C2 is recovered (binary-only)

The command-and-control endpoint is a hardcoded bare-IP HTTP URL compiled directly into the Dart snapshot libapp.so, read out of that file’s string pool. The cluster rotates across a small set of hosting IPs (observed 156.254.21.112, 156.254.21.43, 172.252.173.36, 172.252.224.194, 172.252.224.195, 66.212.58.145). Family label provisional. Indicators: http://172.252.173.36.

Recovered configuration

Source: hardcoded bare-IP base URL compiled into Flutter libapp.so (Jiagu-packed Dalvik layer)

Identification

SHA-256
5a30d9fdfe55eb6e1c52568a2e845d98277060fe86da0932fa6aacec5202a3c9
MD5
4af49b10dbd7baf3f0f4f64a21f39e37

Observed

Families
Flutter SMS Stealer (provisional)
First seen
2026-10-03

APK metadata

Summary

Type
Android · APK
Package
com.ncwtaakvv.rzpyvfqstgw
Main activity
com.ncwtaakvv.rzpyvfqstgw.MainActivity
Internal version
1
Displayed version
1.0.0
Min SDK
24
Target SDK
33

Signing certificate

Valid from
2026-10-02 12:41:31
Valid to
2027-11-05 12:41:31
Serial
ff9acbcf976dbfc3160c24e479682465104d9740
Thumbprint
248172fd8f6392a311f110173610a499b589e757
Subject
C:MK, CN:6U8GVA, L:XSF5UTDJ, O:A3N6K83EN4, ST:2T2H6QS3, OU:XH6UJ7CN, email:[email protected]
Subject email
[email protected]
Issuer
C:MK, CN:6U8GVA, L:XSF5UTDJ, O:A3N6K83EN4, ST:2T2H6QS3, OU:XH6UJ7CN, email:[email protected]

Permissions (18)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.GET_ACCOUNTSandroid.permission.INTERNETandroid.permission.READ_CALL_LOGandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.READ_PHONE_NUMBERSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_SMSandroid.permission.WRITE_CALL_LOGandroid.permission.WRITE_CONTACTSandroid.permission.WRITE_EXTERNAL_STORAGEcom.ncwtaakvv.rzpyvfqstgw.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.ncwtaakvv.rzpyvfqstgw.MainActivity

Services (1)

  • com.lyokone.location.FlutterLocationService

Receivers (1)

  • androidx.profileinstaller.ProfileInstallReceiver

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters - actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
172.252.173.36 ip - http Flutter SMS Stealer (provisional) 2026-10-03

Signing certificate

Subject CN
6U8GVA
Issuer CN
6U8GVA
Fingerprint
f8641f6d078403f25d1ac6055c4045ef306ccc721bed7760d903858e2a930f73

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Flutter SMS Stealer (provisional)

A **Flutter**-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that `.so` file instead of in the usual Android code. **What it does** - Harvests **SMS messages, contacts, call logs and location** and exfiltrates them to the operator. - Ships under the stable packages `com.dataapp.data_collector` and `com.jlsw.jmy`, as well as randomly-named packages (e.g. `com.ncwtaakvv.rzpyvfqstgw`). - Some builds are additionally wrapped with the **Jiagu** commercial packer; the Flutter payload is identical once unpacked. **How the C2 is recovered (binary-only)** The command-and-control endpoint is a hardcoded **bare-IP HTTP** URL compiled directly into the Dart snapshot `libapp.so`, read out of that file's string pool. The cluster rotates across a small set of hosting IPs (observed `156.254.21.112`, `156.254.21.43`, `172.252.173.36`, `172.252.224.194`, `172.252.224.195`, `66.212.58.145`). Family label provisional.