Threat reportMalwareTL-2026-3128
Novinarya: Android stealer hiding its live C2 in a basalam.com shop profile bio
Novinarya: Android stealer hiding its live C2 in a (TL-2026-3128), also tracked as Smart System Security (lure app name), is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Google Android, maps to 14 MITRE ATT&CK techniques (T1406, T1406.002, T1417.002), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-3128
- Threat ID
- TL-2026-3128
- Also known as
- Smart System Security (lure app name)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, cryptocurrency, consumer-banking
- Target regions
- iran
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Novinarya: Android stealer hiding its live C2 in a
Malware and tooling: Novinarya, ZLib - S0086
How Novinarya: Android stealer hiding its live C2 in a works
Novinarya is an Android stealer disguised as a 'Smart System Security' app and distributed via sideloading. It targets 54 cryptocurrency exchanges/wallets and 27 Iranian banking apps, intercepts SMS/notifications (account numbers, balances, OTPs) and harvests credentials through a phishing WebView. It resolves its rotating C2 from an encrypted manifest pointer to a basalam.com profile whose bio decrypts to the live C2, letting the operator rotate servers without shipping new APKs.
Novinarya (package ir.novinarya) is an Iranian-focused Android banking and cryptocurrency credential stealer documented by STAR Labs (Jacob Soo, 2026-10-08). The sample masquerades as a 'Smart System Security' app. The APK ships a thin 18 KB loader (net.swiftnova.bridge) that loads the native library libuibridge_9203.so from attachBaseContext() before any app code runs. The native loader locates the encrypted asset app_cache.db (about 4.79 MB, magic header 0x7fEPDATA), derives a 32-byte RC4 key by XOR-ing two .rodata arrays and rotating left by one bit, drops the first 768 keystream bytes, and zlib-inflates the result into an 11.89 MB Basic4Android (B4A) bundle (classes1.dex 9.5 MB, classes2.dex 2.4 MB). Filename, loader name and key transform are re-randomized per build, while the inner stealer DEX is byte-for-byte identical across all five observed builds.
The stealer requests QUERY_ALL_PACKAGES and INTERNET but no accessibility service and no overlay permission. Credentials are captured through a phishing WebView that loads an operator-controlled URL from the config key WebViewURL, rewrites the User-Agent to remove the '; wv' token so it looks like a regular Chrome browser, and exfiltrates form fields through an injected JavaScript bridge named B4A. The JavaScript grabber is encrypted with a B4A cipher and the page can be screenshotted as base64 JPEG. An smsreceiver broadcast receiver scrapes SMS and notification content using per-bank regular expressions (Farsi patterns for account number, balance and OTP) held in the encrypted X_BANKS manifest meta-data (26,476 bytes base64, AES-CBC, key SHA-256(X_SIG), where X_SIG is 'Who is the real God? Definitely Void.'). The scraper config contains 25 per-bank regex patterns, and the family targets 54 crypto exchanges/wallets (e.g. Nobitex, Wallex, Ramzinex, Trust Wallet, Tronlink, Atomic Wallet) and 27 Iranian banking apps (e.g. Bank Mellat, Bank Melli, Saman, Sepah, Tejarat, Pasargad, Parsian).
C2 resolution uses a dead-drop on the legitimate Iranian social-commerce marketplace Basalam. The encrypted manifest value X_ROUTES is decrypted with AES/CBC/PKCS5 (key SHA-256 of X_CID, 16-byte IV prefix) to https://services.basalam.com/web/v1/core/user/m6AJm5. The malware fetches that URL, reads the JSON field 'bio', takes the first 10 characters as the key seed, base64-decodes the rest and AES-CBC decrypts it into http://theapi.the-x-services.xyz/. The operator rotates C2 by editing the profile bio; no new APK is needed. Earlier builds used dead-drop profile dxoeG7, which has since been banned with its bio emptied; the live profile m6AJm5 (display name 'morteza', created 2023-02-04, last activity 2026-08-31) was not banned at the time of analysis. The code also contains an unused [GITHUB] dead-drop branch. Loot (credentials, OTPs, account data) is AES-encrypted and POSTed as a JSON envelope (clientID, DeviceID, version, payload) to the resolved C2; the manifest also carries a 572-byte RSA-2048 public key (X_RSA, OAEP/SHA-256).
Attribution: the source does not name an actor. Iranian origin is inferred from the targeted banks/exchanges, Farsi SMS-scraper configuration and the choice of an Iranian marketplace as dead drop. Distribution is by sideloading. Severity HIGH is an analyst judgement; there is no CVE or CVSS score.
MITRE ATT&CK techniques used in TL-2026-3128
Defense Evasion
T1406 Obfuscated Files or Information; T1406.002 Software Packing; T1655.001 Match Legitimate Name or Location
Credential Access
Discovery
Command and Control
T1437.001 Web Protocols; T1481 Web Service; T1481.001 Dead Drop Resolver; T1521.001 Symmetric Cryptography; T1521.002 Asymmetric Cryptography
Collection
T1517 Access Notifications; T1636.004 SMS Messages
Execution
Exfiltration
Affected products and versions in Novinarya: Android stealer hiding its live C2 in a
- Google — Android
Vulnerable versions: Devices with sideloaded ir.novinarya APK
Remediation for Novinarya: Android stealer hiding its live C2 in a
Immediate actions
- Block theapi.the-x-services.xyz at DNS, proxy and firewall
- Hunt MDM/EDR inventories for package ir.novinarya, loader package net.swiftnova.bridge and the listed SHA-256 hashes
- Uninstall sideloaded 'Smart System Security' apps and reset banking and exchange credentials and OTP/2FA on affected devices
- Alert on HTTP GETs to services.basalam.com/web/v1/core/user/ paths from non-browser app processes; do not blanket-block basalam.com
Workarounds
- Enable Google Play Protect and keep the sideloading restriction on
- Treat bank and exchange login pages shown inside unfamiliar apps as phishing; use official apps only
Longer-term hardening
- Disallow installation from unknown sources on managed Android devices
- Deploy mobile threat defense that inspects manifest meta-data and native-packed payloads
- Instrument app network sinks for sequential AES-CBC decryption followed by HTTP requests to resolved URLs
- Report the malicious Basalam profile m6AJm5 to Basalam for takedown
Timeline of Novinarya: Android stealer hiding its live C2 in a
- Basalam profile m6AJm5 (display name 'morteza'), later used as the live dead-drop, was created.
- Last recorded activity on Basalam profile m6AJm5, whose bio decrypts to the live C2 theapi.the-x-services.xyz.
- STAR Labs (Jacob Soo) publishes the technical analysis of Novinarya and its Basalam bio dead-drop C2 mechanism.
- Analysis shows the newest build (SHA-256 be165239...) resolves via m6AJm5, which was not banned, to the live C2 http://theapi.the-x-services.xyz/.
- STAR Labs reports four earlier builds (X_CID 5i87c5, q17avl, x2tkqy, kowsv3) used dead-drop profile dxoeG7, which was banned by Basalam with its bio emptied.
- Threadlinqs BeaconBeagle config search for theapi.the-x-services.xyz returned no matches.
Sources cited for Novinarya: Android stealer hiding its live C2 in a
- Novinarya: An Android stealer that hides its live C2 in a shop bio
- Uncovering an Iranian mobile malware campaign (Sophos, related Iranian banking malware context)
- 200 Malicious Apps on Iranian Android Banking Campaign (The Hacker News, related context)
- Iranian mobile banking malware campaign extends its reach (Cyware, related context)
- Rewterz threat alert: 200 malicious Android apps target Iranian banks (related context)
Detection coverage for TL-2026-3128
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3128 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.