# Novinarya: Android stealer hiding its live C2 in a basalam.com shop profile bio

> Novinarya is an Android stealer disguised as a 'Smart System Security' app and distributed via sideloading. It targets 54 cryptocurrency exchanges/wallets and 27 Iranian banking apps, intercepts SMS/notifications (account numbers, balances, OTPs) and harvests credentials through a phishing WebView. It resolves its rotating C2 from an encrypted manifest pointer to a basalam.com profile whose bio decrypts to the live C2, letting the operator rotate servers without shipping new APKs.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3128
- **ID:** TL-2026-3128
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Novinarya (package ir.novinarya) is an Iranian-focused Android banking and cryptocurrency credential stealer documented by STAR Labs (Jacob Soo, 2026-10-08). The sample masquerades as a 'Smart System Security' app. The APK ships a thin 18 KB loader (net.swiftnova.bridge) that loads the native library libuibridge_9203.so from attachBaseContext() before any app code runs. The native loader locates the encrypted asset app_cache.db (about 4.79 MB, magic header 0x7fEPDATA), derives a 32-byte RC4 key by XOR-ing two .rodata arrays and rotating left by one bit, drops the first 768 keystream bytes, and zlib-inflates the result into an 11.89 MB Basic4Android (B4A) bundle (classes1.dex 9.5 MB, classes2.dex 2.4 MB). Filename, loader name and key transform are re-randomized per build, while the inner stealer DEX is byte-for-byte identical across all five observed builds.

The stealer requests QUERY_ALL_PACKAGES and INTERNET but no accessibility service and no overlay permission. Credentials are captured through a phishing WebView that loads an operator-controlled URL from the config key WebViewURL, rewrites the User-Agent to remove the '; wv' token so it looks like a regular Chrome browser, and exfiltrates form fields through an injected JavaScript bridge named B4A. The JavaScript grabber is encrypted with a B4A cipher and the page can be screenshotted as base64 JPEG. An smsreceiver broadcast receiver scrapes SMS and notification content using per-bank regular expressions (Farsi patterns for account number, balance and OTP) held in the encrypted X_BANKS manifest meta-data (26,476 bytes base64, AES-CBC, key SHA-256(X_SIG), where X_SIG is 'Who is the real God? Definitely Void.'). The scraper config contains 25 per-bank regex patterns, and the family targets 54 crypto exchanges/wallets (e.g. Nobitex, Wallex, Ramzinex, Trust Wallet, Tronlink, Atomic Wallet) and 27 Iranian banking apps (e.g. Bank Mellat, Bank Melli, Saman, Sepah, Tejarat, Pasargad, Parsian).

C2 resolution uses a dead-drop on the legitimate Iranian social-commerce marketplace Basalam. The encrypted manifest value X_ROUTES is decrypted with AES/CBC/PKCS5 (key SHA-256 of X_CID, 16-byte IV prefix) to https://services.basalam.com/web/v1/core/user/m6AJm5. The malware fetches that URL, reads the JSON field 'bio', takes the first 10 characters as the key seed, base64-decodes the rest and AES-CBC decrypts it into http://theapi.the-x-services.xyz/. The operator rotates C2 by editing the profile bio; no new APK is needed. Earlier builds used dead-drop profile dxoeG7, which has since been banned with its bio emptied; the live profile m6AJm5 (display name 'morteza', created 2023-02-04, last activity 2026-08-31) was not banned at the time of analysis. The code also contains an unused [GITHUB] dead-drop branch. Loot (credentials, OTPs, account data) is AES-encrypted and POSTed as a JSON envelope (clientID, DeviceID, version, payload) to the resolved C2; the manifest also carries a 572-byte RSA-2048 public key (X_RSA, OAEP/SHA-256).

Attribution: the source does not name an actor. Iranian origin is inferred from the targeted banks/exchanges, Farsi SMS-scraper configuration and the choice of an Iranian marketplace as dead drop. Distribution is by sideloading. Severity HIGH is an analyst judgement; there is no CVE or CVSS score.

## MITRE ATT&CK

- T1655.001 Match Legitimate Name or Location
- T1406 Obfuscated Files or Information
- T1406.002 Software Packing
- T1575 Native API
- T1418 Software Discovery
- T1417.002 GUI Input Capture
- T1636.004 SMS Messages
- T1517 Access Notifications
- T1481 Web Service
- T1481.001 Dead Drop Resolver
- T1437.001 Web Protocols
- T1521.001 Symmetric Cryptography
- T1521.002 Asymmetric Cryptography
- T1646 Exfiltration Over C2 Channel

## Sources

- [Novinarya: An Android stealer that hides its live C2 in a shop bio](https://starlabs.sg/blog/2026/10-novinarya-an-android-stealer-that-hides-its-live-c2-in-a-shop-bio/)
- [Uncovering an Iranian mobile malware campaign (Sophos, related Iranian banking malware context)](https://www.sophos.com/en-us/blog/uncovering-an-iranian-mobile-malware-campaign)
- [200 Malicious Apps on Iranian Android Banking Campaign (The Hacker News, related context)](https://thehackernews.com/2023/11/200-malicious-apps-on-iranian-android.html)
- [Iranian mobile banking malware campaign extends its reach (Cyware, related context)](https://cyware.com/news/unveiling-the-persisting-threat-iranian-mobile-banking-malware-campaign-extends-its-reach-597d4a32)
- [Rewterz threat alert: 200 malicious Android apps target Iranian banks (related context)](https://rewterz.com/rewterz-news/rewterz-threat-alert-emerging-cyber-threat-200-malicious-android-apps-set-sights-on-iranian-banks-active-iocs)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3128
