f720caa316e62abe5b5bc69d…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

UPI OTP Stealer (provisional). India-targeted Android banking stealer focused on UPI (Unified Payments Interface) fraud. Delivered as a dropper, it abuses SMS access to intercept one-time passcodes and harvests UPI/banking credentials, exfiltrating them to its backend (observed at deploy229.cehtech.net). Family label provisional. Indicators: https://deploy229.cehtech.net.

Recovered configuration

package
com.twvcudx.heamtn.nqrp

Identification

SHA-256
f720caa316e62abe5b5bc69d89b76e7b704b82355e23847bd1439f2edc50af89
MD5
cab9f7ac767de47c84483c3cee53e576

Observed

Families
UPI OTP Stealer (provisional)
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
com.twvcudx.heamtn.nqrp
Main activity
com.twvcudx.heamtn.nqrp.CwonJuzks
Internal version
1
Displayed version
1.0
Min SDK
24
Target SDK
35

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (7)

android.permission.ACCESS_NETWORK_STATEandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.REQUEST_INSTALL_PACKAGEScom.twvcudx.heamtn.nqrp.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.twvcudx.heamtn.nqrp.CwonJuzks
  • com.twvcudx.heamtn.nqrp.KHRybunkg

Services (2)

  • com.twvcudx.heamtn.nqrp.BOMDyZJja
  • com.twvcudx.heamtn.nqrp.PATqOsNxi

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • com.twvcudx.heamtn.nqrp.CRbXZIZSi

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters - actions

android.net.VpnServiceandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
deploy229.cehtech.net domain - https UPI OTP Stealer (provisional) 2026-10-07

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About UPI OTP Stealer (provisional)

India-targeted Android banking stealer focused on UPI (Unified Payments Interface) fraud. Delivered as a dropper, it abuses SMS access to intercept one-time passcodes and harvests UPI/banking credentials, exfiltrating them to its backend (observed at deploy229.cehtech.net). Family label provisional.