b920ac40a21947d7f5e5ab60…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

SMS Forwarder (provisional). A broad class of simple Android OTP/SMS stealers (packages like com.example.smsforwarder) that register a RECEIVE_SMS receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only:

  • Telegram bot - the message is sent through the Telegram Bot API; the bot token(s) (<id>:<authstring>) and target chat_id are hardcoded, so api.telegram.org is the C2 and the bot token is the actionable IOC (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback).

  • HTTP drop - the message is POSTed to a hardcoded endpoint, typically a bare IP with an /sms / ingest PHP handler.

Family label is provisional - these are commodity builders, not a single actor. Indicators: http://158.247.219.34/sms/sms_ingest.php.

Identification

SHA-256
b920ac40a21947d7f5e5ab60eb3b246fa409ced892a3eed2fede8aae7eac9530
MD5
ea36f81ce54d3e1ac2d11f17fd29dbe4

Observed

Families
SMS Forwarder (provisional)
First seen
2026-09-27

APK metadata

Summary

Type
Android · APK
Package
com.local.smsforward
Main activity
com.local.smsforward.MainActivity
Internal version
5
Displayed version
1.4
Min SDK
26
Target SDK
34

Signing certificate

Valid from
2026-07-29 23:40:20
Valid to
2053-12-14 23:40:20
Serial
b17fd1d915444e93
Thumbprint
0118750eb321db6707ce0027f68a04a8084a2cf7
Subject
C:KR, CN:SMS Forward Local, L:Seoul, O:Local, ST:Seoul, OU:Personal
Issuer
C:KR, CN:SMS Forward Local, L:Seoul, O:Local, ST:Seoul, OU:Personal

Permissions (4)

android.permission.INTERNETandroid.permission.RECEIVE_SMSandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONScom.local.smsforward.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (1)

  • com.local.smsforward.MainActivity

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • com.local.smsforward.SmsReceiver

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters - actions

android.provider.Telephony.SMS_RECEIVEDandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
158.247.219.34/sms/sms_ingest.php ip - http SMS Forwarder (provisional) 2026-09-27

Signing certificate

Subject CN
SMS Forward Local
Issuer CN
SMS Forward Local
Fingerprint
f193ce635f06f485a84f5980252639879e87d761dfb95ce0289620972c224fb0

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About SMS Forwarder (provisional)

A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.