fd1aac87399ad22234c503d8…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

StrongPity. StrongPity (aka Promethium / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned. Indicators: https://internetwideband.com/user/.

Identification

SHA-256
fd1aac87399ad22234c503d8adb2ae9f0d950b6edf4456b1515a30100b5656a7
MD5
d9d34d6627ae3150bd574b6523995d9a

Observed

Families
StrongPity
First seen
2021-05-24

APK metadata

Summary

Type
Android · APK
Package
com.egov.app
Main activity
com.egov.app.ui.SplashActivity
Internal version
4
Displayed version
1.3
Min SDK
22
Target SDK
22

Signing certificate

Valid from
2020-07-16 16:04:53
Valid to
2045-07-10 16:04:53
Serial
1774a69b
Thumbprint
6714ebd436f81da8a7795f47d74801330c69f189
Subject
C:CA, CN:Elizabeth Mckinsen, L:Toronto, O:Mobility, ST:Toronto, OU:Android Dev Team
Issuer
C:CA, CN:Elizabeth Mckinsen, L:Toronto, O:Mobility, ST:Toronto, OU:Android Dev Team

Permissions (10)

android.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CHANGE_WIFI_STATEandroid.permission.INTERNETandroid.permission.READ_CONTACTSandroid.permission.READ_PHONE_STATEandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGE

Activities (2)

  • com.egov.app.MainActivity
  • com.egov.app.ui.SplashActivity

Services (1)

  • com.egov.app.NetworkStatusService

Receivers (2)

  • com.egov.app.Receiver
  • com.egov.app.UserPresentHandler

Providers (2)

  • androidx.lifecycle.ProcessLifecycleOwnerInitializer
  • com.squareup.picasso.PicassoProvider

Intent filters - actions

android.intent.action.BATTERY_CHANGEDandroid.intent.action.BATTERY_LOWandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.USER_PRESENT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
internetwideband.com/user/ domain - https StrongPity 2021-05-24

Signing certificate

Subject CN
Elizabeth Mckinsen
Issuer CN
Elizabeth Mckinsen
Fingerprint
da944f2879dcb7f7061754f3cec1d59da1eabb78e6b1ba96cfd5daf0acad029f

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About StrongPity

**StrongPity** (aka **Promethium** / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.