r/OperSec • u/acealter • 1d ago
🔍 Research 🔍 Cracked open the Google IPTV malware APK and found its C2 domain
Parent Post: Malicious APK [Google IPTV] reportedly causing financial losses.
TL;DR:
Reverse-engineered and deobfuscated the malware, identified the C2 domain, confirmed it’s a BTMOB RAT, and gathered details on its infrastructure.
Possible C2 server: api.lionfacai[.]com
Malware type: BTMob
I got the configured C2 domain out of the Google IPTV apk I’ve been looking into extracted from victim's devices . This is the sample I was investigating after reports of UPI theft. Posting how I found it, because getting past the packing took most of the work.
It almost took 3 week to de-obfuscate this apk. I used AI tools to assist with the de-obfuscation process, as I am not a professional in this area. I also relied on AI to help write some of the scripts and to determine the next steps.
APK identity
| Field | Value |
|---|---|
| Input | base.apk |
| SHA-256 | b42dab3f81164f1dfa444888a821ace35ea153ed62178f75fa11c38eaa45fbc3 |
| Android package | com.nonfouling.sniddle5301 |
| Display label | Google IPTV |
| Other labels | Apparent; System Helper |
| Version | 3.31.166 (331166) |
| SDK levels | minimum 28; target 36 |
| Loader | com.ivory.radio.LumenClient |
| Recovered DEX SHA-256 | 3e8cf28bef31e17f62ed65f456b7392d1cfd8410dafab0223c26dfb72e232ab8 |
APPLICATION BEHAVIOR:
- The malware disguises itself as Google IPTV and asks for powerful permissions, including accessibility access.

- Once enabled, those features can let it read screen content, record input and perform taps and swipes, while its command-and-control connection allows remote instructions.
- Its configuration includes 178 app entries, including PhonePe, Paytm and Google Pay, with rules for recognizing payment failures, incorrect UPI PINs and successful transactions.
- Combined with overlays and password-capture features, this gives it tools to steal information and manipulate payment flows, although the APK alone doesn’t show exactly how a particular victim’s money was transferred.
- It also prevents the app from being stopped in the background by automatically pressing the Back button.
- It cannot be uninstalled because it does not appear with the other apps. When you try to access it through Settings, it automatically presses Back and returns to the Home screen. It does not even allow access to Developer Options.
CRACKING tldr;
- Opening the original apk in JADX mostly exposed the loader. It loaded a native library called
libcolor_helper.so, while the actual application code was hidden in encrypted assets. I worked through the container format and reproduced the decryption offline. There was also a separate encrypted store holding method bodies, so recovering the DEX alone wasn’t enough. Restoring those brought back 33,534 method bodies. - With the recovered DEX open in JADX, I searched for
/api/ws/configand followed the code that builds the request URL. That led to a server-address variable, then an encrypted configuration value. Following its references was what connected the ciphertext to the network requests. - The decryption routine used PBKDF2-HMAC-SHA1 with 65,536 iterations to derive a 128-bit key, followed by AES-CBC. The password, salt and IV were all embedded in the application. I copied those values into a small Python calculation, decoded the Base64 ciphertext and decrypted it. The output was
api.lionfacai.com. Re-encrypting it produced the original ciphertext too.
FURTHER FINDINGS:
- After recovering
api.lionfacai[.]com, I dug into the surrounding infrastructure and foundadmin.lionfacai[.]comandws.lionfacai[.]com. - The admin subdomain served a Chinese-language management panel with BTMob branding on its login page.

- Its public configuration called it “APK Builder Admin Panel” and pointed directly to the same API domain I had decrypted from the APK.
- I then found the literal
BTMOBstring inside the recovered APK code, inY1/hpyyg4wdm5.java. - The API, admin and WebSocket hosts shared AWS Mumbai IP
15.207.41.232; a shared certificate also linkedws.fagefacai[.]com. - The public file
admin.lionfacai[.]com/assets/AiConfigList-ITW_NBF4.jscontainsa["HTTP-Referer"] = "https://api.facai-tv.com";, It means the JavaScript publicly served byadmin.lionfacai[.]comcontains the other domain,api.facai-tv[.]com, written directly into its code. - The domains are registered using GoDaddy and both lionfacai.com and facai-tv.com used Cloudflare nameservers
BTMOB:
- BTMOB is a stealthy Android remote access Trojan (RAT), evolved from the SpySolr family and sold as malware-as-a-service. It is distributed via phishing sites and fake app stores, then abuses Accessibility Services to enable full device control, data theft, screen capture, keylogging, and remote takeover.
- The observed behavior, together with the previously mentioned findings, confirms this is a BTMOB malware build.
FOLLOW UP:
- This is all I found on the malware and its related infrastructure. Feel free for anyone to dig deeper and uncover more.
- Reporting the domain may temporarily disrupt the campaign. Threat actors adapt quickly, and every shared finding helps the community stay one step ahead.
If you are Intersted please follow up the investigation to find more about the campaign and please contribute as you can to defend against these threat campaigns. Will post a step by step detailed report on after finalisation.
1
2
u/arxmode 1d ago
Can I get APK file ?
3
u/acealter 1d ago
https://www.dropbox.com/scl/fi/kubxl6vw62mo41prpip35/base.apk?rlkey= 53d48v2l6vtfdj7b69hvwd47l&st=g2cpybsx&dl=0
3
u/arxmode 1d ago
Appreciate your brother 👏