9beab3f4aec1f751917443b6…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

HDFC Card Stealer (provisional). HDFC Card Stealer (provisional) is an Android phishing/stealer impersonating HDFC Bank (India). It presents fake card and net-banking entry screens and exfiltrates captured card numbers, CVV, expiry, credentials and OTP data to a Google Firebase backend (hdfc-1-81195-default-rtdb.firebaseio.com and hdfc-1-81195.firebasestorage.app). Part of the wave of India-targeting bank-phishing APKs that use Firebase as a zero-infrastructure exfil endpoint. Indicators: https://hdfc-1-81195-default-rtdb.firebaseio.com, https://hdfc-1-81195.firebasestorage.app.

Recovered configuration

package
com.glgcjkx.xxon

Identification

SHA-256
9beab3f4aec1f751917443b6339abbd071cc7e9096c47410760169d858e4c637
MD5
6431c6f831677f4dd087c85c42adb2c9

Observed

Families
HDFC Card Stealer (provisional)
First seen
2026-10-03

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
hdfc-1-81195-default-rtdb.firebaseio.com domain - https HDFC Card Stealer (provisional) 2026-10-03
hdfc-1-81195.firebasestorage.app domain - https HDFC Card Stealer (provisional) 2026-10-03

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About HDFC Card Stealer (provisional)

**HDFC Card Stealer** (provisional) is an Android phishing/stealer impersonating **HDFC Bank** (India). It presents fake card and net-banking entry screens and exfiltrates captured card numbers, CVV, expiry, credentials and OTP data to a Google Firebase backend (hdfc-1-81195-default-rtdb.firebaseio.com and hdfc-1-81195.firebasestorage.app). Part of the wave of India-targeting bank-phishing APKs that use Firebase as a zero-infrastructure exfil endpoint.