SHA1 hash:
- 766b8e0afa6db3857c8038ab1bbba31e4449d15b
Description
The trojan that downloads and executes remote code. It was first discovered in 2021 by Doctor Web specialists as Android.DownLoader.1051.origin. At that time, it was controlled from the server hxxps[:]//rgk[.]zuoyoo[.]cn.
In 2025, it became part of the Android.Phantom family. Current versions are controlled from the following servers:
- hxxps[:]//fyapi[.]freeflightbird[.]com,
- hxxps[:]//cgb[.]jingongbuxiao[.]com.
Downloaded modules:
The trojan is used in conjunction with the Android.Phantom.5 packer.