5d57a09ee2782dd94a1b11ad…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

RatHat, delivered inside a new AES-256-GCM 2-stage packer (distinct from the Black Hawk XOR packer). Outer fake Rakuten app app.cooltools.hub (楽天ポイント); Java stub net.scout.smartapps.* with strings XOR-0xa5. Each blob = salt(16)∥nonce(12)∥GCM; key = HKDF-SHA256(salt, MASTER), AAD = salt∥kind; plaintext body is XOR-0x57 + nibble-swap + inflate. Asset deb4e823.idx → stage-1 dex → the 17.7 MB e49ca96a asset decrypts to a ZIP = the real RatHat APK. Registration C2 http://177.4.12.41:8889 (ZM26 serverUrl; owner admin; buildTime 2026-05-29T16:45:55+08:00 - same build as cf6fab86…, port 8889). webUrl was the Rakuten lure (filtered). RatHat’s primary channel is a runtime-fetched FRP tunnel, not a static IOC.

Identification

SHA-256
5d57a09ee2782dd94a1b11adb0376041ba42faeb1a8bdbfeaabb83d93d9834b5
MD5
11114051fec3203ee5f2ce82f6dad3e9

Observed

Families
RatHat
First seen
2026-10-04

APK metadata

Summary

Type
Android · APK
Package
app.cooltools.hub
Main activity
app.cooltools.hub.dvmru
Internal version
-
Displayed version
-
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (7)

Decoy loader shell - the real permission set is under Unpacked payload below.

Activities (1)

  • app.cooltools.hub.dvmru

Services (1)

  • app.cooltools.hub.wzmzs

Receivers (1)

  • app.cooltools.hub.egtst

Intent filters - actions

android.net.VpnService

Unpacked payload

The real payload hidden inside the packer, recovered by unwrapping the sample (AES-GCM 2-stage packer). This is the actual capability set the malware runs with - the APK metadata above is only the decoy loader shell.

Summary

Package
com.tool.move.good
Main activity
-
Internal version
50807
Displayed version
5.8.7
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (47)

android.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.AUTHENTICATE_ACCOUNTSandroid.permission.CAMERAandroid.permission.CHANGE_WIFI_STATEandroid.permission.DISABLE_KEYGUARDandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_DATA_SYNCandroid.permission.FOREGROUND_SERVICE_MEDIA_PROJECTIONandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.GET_ACCOUNTSandroid.permission.GET_INSTALLED_APPSandroid.permission.INTERNETandroid.permission.KILL_BACKGROUND_PROCESSESandroid.permission.MANAGE_EXTERNAL_STORAGEandroid.permission.MEDIA_PROJECTIONandroid.permission.MODIFY_AUDIO_SETTINGSandroid.permission.POST_NOTIFICATIONSandroid.permission.QUERY_ALL_PACKAGESandroid.permission.QUICKBOOT_POWERONandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_AUDIOandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.READ_MEDIA_VISUAL_USER_SELECTEDandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.READ_SYNC_SETTINGSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECORD_AUDIOandroid.permission.REORDER_TASKSandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SCHEDULE_EXACT_ALARMandroid.permission.SEND_SMSandroid.permission.SYSTEM_ALERT_WINDOWandroid.permission.TURN_SCREEN_ONandroid.permission.USE_BIOMETRICandroid.permission.USE_EXACT_ALARMandroid.permission.USE_FULL_SCREEN_INTENTandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SECURE_SETTINGSandroid.permission.WRITE_SETTINGScom.huawei.permission.external_app_settings.USE_COMPONENTcom.tool.move.good.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONoppo.permission.OPPO_COMPONENT_SAFE

Activities (18)

  • com.tool.move.good.activity.BackgroundTaskActivity
  • com.tool.move.good.activity.CompatSetupActivity
  • com.tool.move.good.activity.PackageVerifyActivity
  • com.tool.move.good.activity.ServiceConfigActivity
  • com.tool.move.good.activity.TransparentHelperActivity
  • com.tool.move.good.activity.WelcomeActivity
  • com.tool.move.good.activity.dlijjkjhf
  • com.tool.move.good.activity.fosftfvzhthu
  • com.tool.move.good.activity.kmtccjgigqvw
  • com.tool.move.good.activity.mlqpcrfkifay
  • com.tool.move.good.activity.oylyykqz
  • com.tool.move.good.activity.spfixxpk
  • com.tool.move.good.activity.xneysihnjk
  • com.tool.move.good.inject.xhbpqiibi
  • com.tool.move.good.rbrbhutzqr
  • com.tool.move.good.service.modules.yw5xud.levbpgch
  • com.tool.move.good.ui.levbpgch
  • com.tool.move.good.ui.miekbmlrugbv

Services (13)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.tool.move.good.activity.Coreampgxtgnoyh
  • com.tool.move.good.keepalive.guard.cflzuusapuen1
  • com.tool.move.good.keepalive.guard.cflzuusapuen2
  • com.tool.move.good.service.AppCoreService
  • com.tool.move.good.service.InitWorkerService
  • com.tool.move.good.service.MediaDisplayService
  • com.tool.move.good.service.dujavtainhyy
  • com.tool.move.good.service.qikbhrfckp
  • com.tool.move.good.service.udzwjtyarwv

Receivers (19)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy.StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • androidx.work.impl.utils.ForceStopRunnable.BroadcastReceiver
  • com.tool.move.good.receiver.cydcbdmt
  • com.tool.move.good.receiver.vaepezxil
  • com.tool.move.good.service.bepnvagkvd
  • com.tool.move.good.service.kdkkyjresp
  • com.tool.move.good.service.modules.cybyorzcc

Providers (2)

  • androidx.startup.InitializationProvider
  • com.tool.move.good.provider.EarlyInitProvider

Intent filters - actions

android.accessibilityservice.AccessibilityServiceandroid.app.action.ACTION_PASSWORD_CHANGEDandroid.app.action.ACTION_PASSWORD_EXPIRINGandroid.app.action.ACTION_PASSWORD_FAILEDandroid.app.action.ACTION_PASSWORD_SUCCEEDEDandroid.app.action.DEVICE_ADMIN_DISABLEDandroid.app.action.DEVICE_ADMIN_DISABLE_REQUESTEDandroid.app.action.DEVICE_ADMIN_ENABLEDandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.ACTION_SHUTDOWNandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.LOCKED_BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.PACKAGE_ADDEDandroid.intent.action.PACKAGE_CHANGEDandroid.intent.action.PACKAGE_REMOVEDandroid.intent.action.PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.SCREEN_ONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.intent.action.USER_PRESENTandroid.net.conn.CONNECTIVITY_CHANGEandroid.service.notification.NotificationListenerServiceandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.htc.intent.action.QUICKBOOT_POWERONcom.tool.move.good.action.BACKUP_SYNCcom.tool.move.good.action.HEALTH_CHECKcom.tool.move.good.action.QUICK_SYNC

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
177.4.12.41 ip 8889 http RatHat 2026-10-04

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About RatHat

AI-powered Android credential stealer / RAT (Zimperium, Sep 2026) posing as reward or finance apps (`Tether`, `ReelShort` lures). It serialises the live Accessibility tree to XML and queries Google **Gemini** to resolve on-screen targets and drive synthetic clicks - letting it read and operate banking and wallet apps on the victim's behalf without a human operator. Heavily hardened against analysis: a ~61 MB `AndroidManifest.xml` padded with `0x9999`-byte junk chunks, DEX poisoning (deliberately malformed bytecode that breaks naïve disassemblers), `StringFog`/`StringCrypto` string encryption and ZIP tampering. Configuration lives in a **ZM26 container** under `assets/` - RatHat's own encrypted-blob format: a 4-byte `ZM26` magic, an 8-byte salt, then the payload XOR'd with a repeating 24-byte key (the per-sample `xor_key` from `assets/zm26_meta.json`, concatenated with that salt). The C2 is the `serverUrl` field of `server_config.json` - recoverable in plaintext in some builds, `ZM26`-encrypted in others. The primary FRP tunnel C2 is not a static indicator: it is fetched at runtime by the bundled Go agent `liblocal-service.so`, while `libmedia_codec.so` masquerades as the `frpc` tunnel client.