80656cdb810bf40686f6f6da…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Black Hawk (黑鹰安卓远控). Fake e-Tax app: outer package com.link.clean.work, display name e-Taxソフト. Same native XOR packer: Sa + libsa.so decrypt asset ddkhczhgaiudj with a 32-byte key; PaIslX9k8K4 (17.7 MB) is decoy padding. Inner trojan package com.mobile.nest.simple. C2 https://www.collectpointsjp.com (shared with the Rakuten sample 429c9de4…). Per-build AES-256 exfil key (Cf.K1): fb661dbf254655e3062374545410dd59b5d0c0aeb40b79e322f7f06390f876ad.

Identification

SHA-256
80656cdb810bf40686f6f6da9731addf210d93f8cc417d8b43a3794b57b61010
MD5
6a6a4b0001597b04353562deac311a97

Observed

Families
Black Hawk
First seen
2026-10-03

APK metadata

Summary

Type
Android · APK
Package
com.link.clean.work
Main activity
com.link.clean.work.MainActivity
Internal version
50078
Displayed version
5.0.78
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (4)

Decoy loader shell - the real permission set is under Unpacked payload below.

Activities (2)

  • com.link.clean.work.MainActivity
  • com.link.clean.work.Wv

Services (1)

  • com.link.clean.work.Bv

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • com.link.clean.work.Ir

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters - actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEcom.link.clean.work.INSTALL_COMPLETE

Unpacked payload

The real payload hidden inside the packer, recovered by unwrapping the sample (Black Hawk native XOR packer (installed banker APK)). This is the actual capability set the malware runs with - the APK metadata above is only the decoy loader shell.

Summary

Package
com.mobile.nest.simple
Main activity
-
Internal version
30422
Displayed version
3.4.22
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (51)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.ANSWER_PHONE_CALLSandroid.permission.CALL_PHONEandroid.permission.CAMERAandroid.permission.CHANGE_WIFI_STATEandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_CAMERAandroid.permission.FOREGROUND_SERVICE_LOCATIONandroid.permission.FOREGROUND_SERVICE_MEDIA_PROJECTIONandroid.permission.FOREGROUND_SERVICE_MICROPHONEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.GET_ACCOUNTSandroid.permission.INTERNETandroid.permission.MANAGE_EXTERNAL_STORAGEandroid.permission.POST_NOTIFICATIONSandroid.permission.QUERY_ALL_PACKAGESandroid.permission.READ_CALL_LOGandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_AUDIOandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.READ_MEDIA_VISUAL_USER_SELECTEDandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.RECORD_AUDIOandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SCHEDULE_EXACT_ALARMandroid.permission.SEND_SMSandroid.permission.USE_BIOMETRICandroid.permission.USE_CREDENTIALSandroid.permission.USE_EXACT_ALARMandroid.permission.USE_FULL_SCREEN_INTENTandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SECURE_SETTINGSandroid.permission.WRITE_SETTINGScom.coloros.permission.SAFE_COMPONENTcom.google.android.c2dm.permission.RECEIVEcom.miui.permission.START_IN_BACKGROUNDcom.mobile.nest.simple.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONcom.samsung.android.permission.BACKGROUND_START_ACTIVITYcom.vivo.abe.permission.CLEAN_NOTIFICATIONcom.vivo.permission.manage.permission.ACCESScom.xiaomi.permission.BACKGROUND_START_ACTIVITYoppo.permission.OPPO_COMPONENT_SAFE

Activities (8)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.mobile.nest.simple.activity.AccGuideActivity
  • com.mobile.nest.simple.activity.GrantRequestPage
  • com.mobile.nest.simple.activity.MainGateway
  • com.mobile.nest.simple.activity.SplashGateway
  • com.mobile.nest.simple.activity.WakeScreenPage
  • com.mobile.nest.simple.features.credential.CredentialPromptActivity
  • com.mobile.nest.simple.inject.WebPayloadPage

Services (18)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService
  • com.mobile.nest.simple.features.screen.ScreenCastService
  • com.mobile.nest.simple.keepalive.AdminKeepAliveDaemon
  • com.mobile.nest.simple.keepalive.FcmWakeService
  • com.mobile.nest.simple.keepalive.KeepAliveMediaBrowserService
  • com.mobile.nest.simple.keepalive.KeepAliveMediaRouteService
  • com.mobile.nest.simple.keepalive.KeepAliveTileService
  • com.mobile.nest.simple.keepalive.RecoveryJobService
  • com.mobile.nest.simple.service.CoreTaskAgent
  • com.mobile.nest.simple.service.NotificationListener
  • com.mobile.nest.simple.service.PlatformAssistDaemon

Receivers (16)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver
  • com.mobile.nest.simple.keepalive.AdminEventReceiver
  • com.mobile.nest.simple.keepalive.AlarmKeepAliveReceiver
  • com.mobile.nest.simple.keepalive.KeepAliveWidgetProvider
  • com.mobile.nest.simple.receiver.BootReceiver
  • com.mobile.nest.simple.receiver.PackageEventReceiver

Providers (4)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider
  • com.mobile.nest.simple.keepalive.KeepAliveProvider

Intent filters - actions

android.accessibilityservice.AccessibilityServiceandroid.app.action.DEVICE_ADMIN_DISABLEDandroid.app.action.DEVICE_ADMIN_DISABLE_REQUESTEDandroid.app.action.DEVICE_ADMIN_ENABLEDandroid.appwidget.action.APPWIDGET_UPDATEandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.ACTION_SHUTDOWNandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.LOCKED_BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.PACKAGE_ADDEDandroid.intent.action.PACKAGE_CHANGEDandroid.intent.action.PACKAGE_REMOVEDandroid.intent.action.PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.SCREEN_ONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.intent.action.USER_PRESENTandroid.media.MediaRouteProviderServiceandroid.media.browse.MediaBrowserServiceandroid.net.conn.CONNECTIVITY_CHANGEandroid.service.notification.NotificationListenerServiceandroid.service.quicksettings.action.QS_TILEandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.coloros.intent.action.BOOT_COMPLETEDcom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENTcom.htc.intent.action.QUICKBOOT_POWERONcom.huawei.intent.action.BOOT_COMPLETEDcom.huawei.systemmanager.optimize.bootStart.action.BOOTcom.meizu.intent.action.BOOTcom.miui.intent.action.BOOT_COMPLETEDcom.oppo.intent.action.BOOT_COMPLETEDcom.samsung.android.intent.action.BOOT_COMPLETEDcom.vivo.intent.action.BOOT_COMPLETED

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
www.collectpointsjp.com domain - https Black Hawk 2026-10-03

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.