Threat reportMalwareTL-2026-3128

Novinarya: Android stealer hiding its live C2 in a basalam.com shop profile bio

highACTIVE

Novinarya: Android stealer hiding its live C2 in a (TL-2026-3128), also tracked as Smart System Security (lure app name), is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Google Android, maps to 14 MITRE ATT&CK techniques (T1406, T1406.002, T1417.002), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-3128

Threat ID
TL-2026-3128
Also known as
Smart System Security (lure app name)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, cryptocurrency, consumer-banking
Target regions
iran
Detection rules
9
Indicators of compromise
21

Malware and tooling in Novinarya: Android stealer hiding its live C2 in a

Malware and tooling: Novinarya, ZLib - S0086

How Novinarya: Android stealer hiding its live C2 in a works

Novinarya is an Android stealer disguised as a 'Smart System Security' app and distributed via sideloading. It targets 54 cryptocurrency exchanges/wallets and 27 Iranian banking apps, intercepts SMS/notifications (account numbers, balances, OTPs) and harvests credentials through a phishing WebView. It resolves its rotating C2 from an encrypted manifest pointer to a basalam.com profile whose bio decrypts to the live C2, letting the operator rotate servers without shipping new APKs.

Novinarya (package ir.novinarya) is an Iranian-focused Android banking and cryptocurrency credential stealer documented by STAR Labs (Jacob Soo, 2026-10-08). The sample masquerades as a 'Smart System Security' app. The APK ships a thin 18 KB loader (net.swiftnova.bridge) that loads the native library libuibridge_9203.so from attachBaseContext() before any app code runs. The native loader locates the encrypted asset app_cache.db (about 4.79 MB, magic header 0x7fEPDATA), derives a 32-byte RC4 key by XOR-ing two .rodata arrays and rotating left by one bit, drops the first 768 keystream bytes, and zlib-inflates the result into an 11.89 MB Basic4Android (B4A) bundle (classes1.dex 9.5 MB, classes2.dex 2.4 MB). Filename, loader name and key transform are re-randomized per build, while the inner stealer DEX is byte-for-byte identical across all five observed builds.

The stealer requests QUERY_ALL_PACKAGES and INTERNET but no accessibility service and no overlay permission. Credentials are captured through a phishing WebView that loads an operator-controlled URL from the config key WebViewURL, rewrites the User-Agent to remove the '; wv' token so it looks like a regular Chrome browser, and exfiltrates form fields through an injected JavaScript bridge named B4A. The JavaScript grabber is encrypted with a B4A cipher and the page can be screenshotted as base64 JPEG. An smsreceiver broadcast receiver scrapes SMS and notification content using per-bank regular expressions (Farsi patterns for account number, balance and OTP) held in the encrypted X_BANKS manifest meta-data (26,476 bytes base64, AES-CBC, key SHA-256(X_SIG), where X_SIG is 'Who is the real God? Definitely Void.'). The scraper config contains 25 per-bank regex patterns, and the family targets 54 crypto exchanges/wallets (e.g. Nobitex, Wallex, Ramzinex, Trust Wallet, Tronlink, Atomic Wallet) and 27 Iranian banking apps (e.g. Bank Mellat, Bank Melli, Saman, Sepah, Tejarat, Pasargad, Parsian).

C2 resolution uses a dead-drop on the legitimate Iranian social-commerce marketplace Basalam. The encrypted manifest value X_ROUTES is decrypted with AES/CBC/PKCS5 (key SHA-256 of X_CID, 16-byte IV prefix) to https://services.basalam.com/web/v1/core/user/m6AJm5. The malware fetches that URL, reads the JSON field 'bio', takes the first 10 characters as the key seed, base64-decodes the rest and AES-CBC decrypts it into http://theapi.the-x-services.xyz/. The operator rotates C2 by editing the profile bio; no new APK is needed. Earlier builds used dead-drop profile dxoeG7, which has since been banned with its bio emptied; the live profile m6AJm5 (display name 'morteza', created 2023-02-04, last activity 2026-08-31) was not banned at the time of analysis. The code also contains an unused [GITHUB] dead-drop branch. Loot (credentials, OTPs, account data) is AES-encrypted and POSTed as a JSON envelope (clientID, DeviceID, version, payload) to the resolved C2; the manifest also carries a 572-byte RSA-2048 public key (X_RSA, OAEP/SHA-256).

Attribution: the source does not name an actor. Iranian origin is inferred from the targeted banks/exchanges, Farsi SMS-scraper configuration and the choice of an Iranian marketplace as dead drop. Distribution is by sideloading. Severity HIGH is an analyst judgement; there is no CVE or CVSS score.

MITRE ATT&CK techniques used in TL-2026-3128

Defense Evasion

T1406 Obfuscated Files or Information; T1406.002 Software Packing; T1655.001 Match Legitimate Name or Location

Credential Access

T1417.002 GUI Input Capture

Discovery

T1418 Software Discovery

Command and Control

T1437.001 Web Protocols; T1481 Web Service; T1481.001 Dead Drop Resolver; T1521.001 Symmetric Cryptography; T1521.002 Asymmetric Cryptography

Collection

T1517 Access Notifications; T1636.004 SMS Messages

Execution

T1575 Native API

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in Novinarya: Android stealer hiding its live C2 in a

  • Google — Android
    Vulnerable versions: Devices with sideloaded ir.novinarya APK

Remediation for Novinarya: Android stealer hiding its live C2 in a

Immediate actions

  • Block theapi.the-x-services.xyz at DNS, proxy and firewall
  • Hunt MDM/EDR inventories for package ir.novinarya, loader package net.swiftnova.bridge and the listed SHA-256 hashes
  • Uninstall sideloaded 'Smart System Security' apps and reset banking and exchange credentials and OTP/2FA on affected devices
  • Alert on HTTP GETs to services.basalam.com/web/v1/core/user/ paths from non-browser app processes; do not blanket-block basalam.com

Workarounds

  • Enable Google Play Protect and keep the sideloading restriction on
  • Treat bank and exchange login pages shown inside unfamiliar apps as phishing; use official apps only

Longer-term hardening

  • Disallow installation from unknown sources on managed Android devices
  • Deploy mobile threat defense that inspects manifest meta-data and native-packed payloads
  • Instrument app network sinks for sequential AES-CBC decryption followed by HTTP requests to resolved URLs
  • Report the malicious Basalam profile m6AJm5 to Basalam for takedown

Timeline of Novinarya: Android stealer hiding its live C2 in a

  • Basalam profile m6AJm5 (display name 'morteza'), later used as the live dead-drop, was created.
  • Last recorded activity on Basalam profile m6AJm5, whose bio decrypts to the live C2 theapi.the-x-services.xyz.
  • STAR Labs (Jacob Soo) publishes the technical analysis of Novinarya and its Basalam bio dead-drop C2 mechanism.
  • Analysis shows the newest build (SHA-256 be165239...) resolves via m6AJm5, which was not banned, to the live C2 http://theapi.the-x-services.xyz/.
  • STAR Labs reports four earlier builds (X_CID 5i87c5, q17avl, x2tkqy, kowsv3) used dead-drop profile dxoeG7, which was banned by Basalam with its bio emptied.
  • Threadlinqs BeaconBeagle config search for theapi.the-x-services.xyz returned no matches.

Sources cited for Novinarya: Android stealer hiding its live C2 in a

Detection coverage for TL-2026-3128

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3128 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats