Brokewell: recovered C2 indicators & analysis
A device-takeover Android banking trojan that abuses the Accessibility service to log input, overlay banking apps, stream the screen, and give operators full remote control of infected devices.
What Brokewell is
Brokewell is an Android banking trojan first publicly documented by ThreatFabric in April 2024 after analysts found a fake browser-update page delivering the malware; retrospective analysis tied it to earlier campaigns impersonating a buy-now-pay-later service (Klarna) and an Austrian digital-authentication app (ID Austria).
It is a dual-purpose threat: a traditional overlay/credential-stealing banker combined with extensive remote-access-trojan (device takeover) functionality, implementing on the order of 50-60 operator commands.
Distribution is via social-engineering pages that masquerade as legitimate app updates, most notably fake Google Chrome update prompts shown during web browsing.
The malware is attributed to a threat actor using the alias 'Baron Samedit', who runs a project called 'Brokewell Cyber Labs' and had previously sold stolen-account checking tools for roughly two years before pivoting to mobile malware development.
The actor also publishes a companion dropper, the 'Brokewell Android Loader', hosted on a self-run Gitea instance, which is designed to bypass the Accessibility-service side-loading restrictions Google introduced in Android 13 and later.
The malware was observed with a German-language lock screen (suggesting initial targeting of users in Germany) but contains multilingual strings, and reporting describes it as under active development with new commands added frequently.
Capabilities
- Overlay attacks: displays fake login windows over targeted banking and financial apps to harvest credentials
- Accessibility logging / keylogging: captures touches, swipes, text input, on-screen content, and opened applications via the Accessibility service
- Cookie/session theft: loads legitimate sites in its own WebView and exfiltrates the resulting session cookies
- Screen streaming and screen recording via Android MediaProjection for real-time operator visibility
- Full device takeover / remote control: remote clicks, swipes, gestures, text entry, Back/Home/Recents presses, screen unlock, and brightness/volume adjustment
- Microphone audio recording
- Call log (call history) collection
- Geolocation tracking
- Device and installed-software enumeration
- Bypasses Android 13+ Accessibility restrictions via the companion Brokewell Android Loader dropper
- Remote app installation and general on-device action execution on the victim's behalf
Known C2 / channel types: Raw TCP sockets over non-standard ports, HTTP(S) exfiltration endpoints, Real-time screen streaming (MediaProjection).
MITRE ATT&CK (Mobile)
Techniques commonly associated with Brokewell:
| ID | Technique |
|---|---|
| T1660 | Phishing |
| T1655.001 | Masquerading: Match Legitimate Name or Location |
| T1417.001 | Input Capture: Keylogging |
| T1417.002 | Input Capture: GUI Input Capture |
| T1516 | Input Injection |
| T1513 | Screen Capture |
| T1429 | Audio Capture |
| T1430 | Location Tracking |
| T1636.002 | Protected User Data: Call Log |
| T1437 | Application Layer Protocol |
What Privara Unmask recovered
Two Brokewell samples from the corpus were analyzed. The dropper sample identified below is a no-warm-process stage from which no live C2 could be recovered on-device — the honest gap (it needs offline payload decryption). A second Brokewell sample executed and yielded the C2 mi6.operationanonrecoil.ru, which independently matches Brokewell's publicly documented infrastructure (actor "Baron Samedit" / Brokewell Cyber Labs; ThreatFabric, Cyble) — an independent match against ground truth rather than a novel claim. The analysis ran on a de-emulated Android 17 device that the sample could not fingerprint as virtual, so it behaved as it would on a real handset.
SHA-256 48b2095d9f746bb60ddf126365a9bb9ebaeae36f21dc1b5fa2213eafbdc9f18b
Source MalwareBazaar (abuse.ch)
Indicators of compromise (IOCs)
| Indicator | Type | Role | Confidence | Status |
|---|---|---|---|---|
| mi6.operationanonrecoil.ru documented Brokewell C2 (actor "Baron Samedit" / Brokewell Cyber Labs); historically resolved to 91.92.247.182 | domain | C2 | high | offline |
External references
- Brokewell: do not go broke by new banking malware!ThreatFabric
- Brokewell: A New Android Banking Trojan Targeting Users in GermanyCyble
- New Brokewell malware takes over Android devices, steals dataBleepingComputer
- New 'Brokewell' Android Malware Spread Through Fake Browser UpdatesThe Hacker News
- Powerful 'Brokewell' Android Trojan Allows Attackers to Takeover DevicesSecurityWeek
- Android Malware Brokewell With Complete Device Takeover CapabilitiesGBHackers
Methodology & honest limits
This sample was obtained from MalwareBazaar and detonated in a controlled, isolated environment. C2 identity was recovered from the executing sample and its configuration. We report only what the analysis established: an offline sample yields a C2 identity, not a live beacon, and we say so. Nothing here is inferred beyond the evidence.
Analyze your own Android samples like this
Privara Unmask detonates arm64 samples on a de-emulated Android 17 device that anti-analysis code can't fingerprint — recovering C2, config and IOCs automatically, with a clean rollback per sample.
See the sandbox → Request a demo