Threat ResearchAndroid banking trojan (device-takeover banker with RAT/spyware capabilities)April 2024Analyzed 2026-09-08

Brokewell: recovered C2 indicators & analysis

A device-takeover Android banking trojan that abuses the Accessibility service to log input, overlay banking apps, stream the screen, and give operators full remote control of infected devices.

What Brokewell is

Brokewell is an Android banking trojan first publicly documented by ThreatFabric in April 2024 after analysts found a fake browser-update page delivering the malware; retrospective analysis tied it to earlier campaigns impersonating a buy-now-pay-later service (Klarna) and an Austrian digital-authentication app (ID Austria).

It is a dual-purpose threat: a traditional overlay/credential-stealing banker combined with extensive remote-access-trojan (device takeover) functionality, implementing on the order of 50-60 operator commands.

Distribution is via social-engineering pages that masquerade as legitimate app updates, most notably fake Google Chrome update prompts shown during web browsing.

The malware is attributed to a threat actor using the alias 'Baron Samedit', who runs a project called 'Brokewell Cyber Labs' and had previously sold stolen-account checking tools for roughly two years before pivoting to mobile malware development.

The actor also publishes a companion dropper, the 'Brokewell Android Loader', hosted on a self-run Gitea instance, which is designed to bypass the Accessibility-service side-loading restrictions Google introduced in Android 13 and later.

The malware was observed with a German-language lock screen (suggesting initial targeting of users in Germany) but contains multilingual strings, and reporting describes it as under active development with new commands added frequently.

Capabilities

Known C2 / channel types: Raw TCP sockets over non-standard ports, HTTP(S) exfiltration endpoints, Real-time screen streaming (MediaProjection).

MITRE ATT&CK (Mobile)

Techniques commonly associated with Brokewell:

IDTechnique
T1660Phishing
T1655.001Masquerading: Match Legitimate Name or Location
T1417.001Input Capture: Keylogging
T1417.002Input Capture: GUI Input Capture
T1516Input Injection
T1513Screen Capture
T1429Audio Capture
T1430Location Tracking
T1636.002Protected User Data: Call Log
T1437Application Layer Protocol

What Privara Unmask recovered

Two Brokewell samples from the corpus were analyzed. The dropper sample identified below is a no-warm-process stage from which no live C2 could be recovered on-device — the honest gap (it needs offline payload decryption). A second Brokewell sample executed and yielded the C2 mi6.operationanonrecoil.ru, which independently matches Brokewell's publicly documented infrastructure (actor "Baron Samedit" / Brokewell Cyber Labs; ThreatFabric, Cyble) — an independent match against ground truth rather than a novel claim. The analysis ran on a de-emulated Android 17 device that the sample could not fingerprint as virtual, so it behaved as it would on a real handset.

Package xyIBgcE.FKnaCEV.XDKUPweO
SHA-256 48b2095d9f746bb60ddf126365a9bb9ebaeae36f21dc1b5fa2213eafbdc9f18b
Source MalwareBazaar (abuse.ch)

Indicators of compromise (IOCs)

IndicatorTypeRoleConfidenceStatus
mi6.operationanonrecoil.ru
documented Brokewell C2 (actor "Baron Samedit" / Brokewell Cyber Labs); historically resolved to 91.92.247.182
domainC2highoffline
Status note. The indicators above were unresponsive (offline / sinkholed) at analysis time and are published as historical threat intelligence. Co-observed benign and environmental artifacts have been removed rather than reported as C2.

External references

Methodology & honest limits

This sample was obtained from MalwareBazaar and detonated in a controlled, isolated environment. C2 identity was recovered from the executing sample and its configuration. We report only what the analysis established: an offline sample yields a C2 identity, not a live beacon, and we say so. Nothing here is inferred beyond the evidence.

Analyze your own Android samples like this

Privara Unmask detonates arm64 samples on a de-emulated Android 17 device that anti-analysis code can't fingerprint — recovering C2, config and IOCs automatically, with a clean rollback per sample.

See the sandbox → Request a demo