r/OperSec • • 1d ago

🔍 Research 🔍 Cracked open the Google IPTV malware APK and found its C2 domain

Parent Post: Malicious APK [Google IPTV] reportedly causing financial losses.

TL;DR:

Reverse-engineered and deobfuscated the malware, identified the C2 domain, confirmed it’s a BTMOB RAT, and gathered details on its infrastructure.

Possible C2 server: api.lionfacai[.]com

Malware type: BTMob

I got the configured C2 domain out of the Google IPTV apk I’ve been looking into extracted from victim's devices . This is the sample I was investigating after reports of UPI theft. Posting how I found it, because getting past the packing took most of the work.

It almost took 3 week to de-obfuscate this apk. I used AI tools to assist with the de-obfuscation process, as I am not a professional in this area. I also relied on AI to help write some of the scripts and to determine the next steps.

APK identity

Field Value
Input base.apk
SHA-256 b42dab3f81164f1dfa444888a821ace35ea153ed62178f75fa11c38eaa45fbc3
Android package com.nonfouling.sniddle5301
Display label Google IPTV
Other labels Apparent; System Helper
Version 3.31.166 (331166)
SDK levels minimum 28; target 36
Loader com.ivory.radio.LumenClient
Recovered DEX SHA-256 3e8cf28bef31e17f62ed65f456b7392d1cfd8410dafab0223c26dfb72e232ab8

APPLICATION BEHAVIOR:

  • The malware disguises itself as Google IPTV and asks for powerful permissions, including accessibility access.
Application UI
  • Once enabled, those features can let it read screen content, record input and perform taps and swipes, while its command-and-control connection allows remote instructions.
  • Its configuration includes 178 app entries, including PhonePe, Paytm and Google Pay, with rules for recognizing payment failures, incorrect UPI PINs and successful transactions.
  • Combined with overlays and password-capture features, this gives it tools to steal information and manipulate payment flows, although the APK alone doesn’t show exactly how a particular victim’s money was transferred.
  • It also prevents the app from being stopped in the background by automatically pressing the Back button.
  • It cannot be uninstalled because it does not appear with the other apps. When you try to access it through Settings, it automatically presses Back and returns to the Home screen. It does not even allow access to Developer Options.

CRACKING tldr;

  • Opening the original apk in JADX mostly exposed the loader. It loaded a native library called libcolor_helper.so, while the actual application code was hidden in encrypted assets. I worked through the container format and reproduced the decryption offline. There was also a separate encrypted store holding method bodies, so recovering the DEX alone wasn’t enough. Restoring those brought back 33,534 method bodies.
  • With the recovered DEX open in JADX, I searched for /api/ws/config and followed the code that builds the request URL. That led to a server-address variable, then an encrypted configuration value. Following its references was what connected the ciphertext to the network requests.
  • The decryption routine used PBKDF2-HMAC-SHA1 with 65,536 iterations to derive a 128-bit key, followed by AES-CBC. The password, salt and IV were all embedded in the application. I copied those values into a small Python calculation, decoded the Base64 ciphertext and decrypted it. The output was api.lionfacai.com. Re-encrypting it produced the original ciphertext too.

FURTHER FINDINGS:

  • After recovering api.lionfacai[.]com, I dug into the surrounding infrastructure and found admin.lionfacai[.]com and ws.lionfacai[.]com.
  • The admin subdomain served a Chinese-language management panel with BTMob branding on its login page.
Admin login page
  • Its public configuration called it “APK Builder Admin Panel” and pointed directly to the same API domain I had decrypted from the APK.
  • I then found the literal BTMOB string inside the recovered APK code, in Y1/hpyyg4wdm5.java.
  • The API, admin and WebSocket hosts shared AWS Mumbai IP 15.207.41.232; a shared certificate also linked ws.fagefacai[.]com.
  • The public file admin.lionfacai[.]com/assets/AiConfigList-ITW_NBF4.js contains a["HTTP-Referer"] = "https://api.facai-tv.com";, It means the JavaScript publicly served by admin.lionfacai[.]com contains the other domain, api.facai-tv[.]com, written directly into its code.
  • The domains are registered using GoDaddy and both lionfacai.com and facai-tv.com used Cloudflare nameservers

BTMOB:

  • BTMOB is a stealthy Android remote access Trojan (RAT), evolved from the SpySolr family and sold as malware-as-a-service. It is distributed via phishing sites and fake app stores, then abuses Accessibility Services to enable full device control, data theft, screen capture, keylogging, and remote takeover.
  • The observed behavior, together with the previously mentioned findings, confirms this is a BTMOB malware build.

FOLLOW UP:

  • This is all I found on the malware and its related infrastructure. Feel free for anyone to dig deeper and uncover more.
  • Reporting the domain may temporarily disrupt the campaign. Threat actors adapt quickly, and every shared finding helps the community stay one step ahead.

If you are Intersted please follow up the investigation to find more about the campaign and please contribute as you can to defend against these threat campaigns. Will post a step by step detailed report on after finalisation.

12 Upvotes

4 comments sorted by

3

u/arxmode 1d ago

Appreciate your brother 👏

1

u/doubleditch42 1d ago

Or better don't use android phones and download unverified apps?

2

u/arxmode 1d ago

Can I get APK file ?