An honest measurement of what our automated Android malware‑analysis engine recovers — and, just as importantly, where it doesn't yet. Every indicator below is either independently corroborated against public threat intelligence or contributed to the abuse.ch ThreatFox community feed.
Real samples, sourced from MalwareBazaar, detonated on a de‑emulated Android 17 device that anti‑analysis code can't fingerprint as virtual.
Each sample runs in an isolated, per‑sample environment. Privara Unmask drives it past its activation gates (accessibility, locale, target‑app, SMS/OTP and push triggers), unpacks packed and dropper stages, and recovers command‑and‑control and indicators from what the running sample reveals. We publish a C2 only when the evidence backs it, distinguish a recovered identity from a live beacon, and remove shared or benign infrastructure rather than inflate the count. We do not disclose how the de‑emulation itself is built.
"Corroborated" = our recovery independently matches infrastructure already documented by abuse.ch or a named vendor (validation against ground truth). "Contributed" = intelligence we submitted to the ThreatFox community feed.
| Family | Recovered C2 (example) | Verification |
|---|---|---|
| HookOverlay banker / RAT | hrjob‑forward‑build.store | Corroborated |
| ERMACOverlay banker | 193.222.96.48:3434 | Corroborated |
| CerberusPacked banker | 217.8.117.30:80 | Corroborated |
| BrokewellDevice‑takeover banker | mi6.operationanonrecoil.ru | Corroborated |
| TrickMoAccessibility banker | btceducationcenter.com | Contributed |
| GodfatherOn‑device‑fraud banker | Telegram dead‑drop channels | Contributed |
| BingoModOn‑device‑fraud RAT | 23.254.226.46:8055 · :13500 | Contributed |
| SoumniBotManifest‑obfuscated banker | 54.162.26.208:29221 · MQTT :1883 | Contributed |
| Coper / OctoTarget‑app‑gated banker | 5 × .shop C2 domains | Contributed |
| FluhorseCredential / 2FA stealer | jp.yelove.xyz | Contributed |
| MamontLocale‑gated stealer | 194.41.113.39:8081 | Contributed |
| Anubis‑familyPacked a11y dropper | jsonserv.biz/app‑store | Contributed |
| mParivahan‑familyFirebase‑C2 dropper | Firebase RTDB endpoint | Recovered |
A sandbox that finds something in everything is worse than one that says when it didn't. These are documented honestly as the current coverage tail — never reported as findings.
| Family | Outcome | Why — and what it is, not |
|---|---|---|
| VulturVNC banker | Did not detonate | Did not execute its payload in this environment across two attempts; a per‑run outcome and a retry candidate — not a confirmed clean verdict. |
| SpyNoteGeneric RAT | Did not detonate | As above — did not execute this run; flagged for re‑detonation, not misreported as benign. |
This isn't a claim — the intelligence is public and checkable.
Full write‑ups for each recovered family, with recovered indicators, MITRE ATT&CK mapping and cited sources.
tajapps.com/research →Indicators submitted under our verified community account — traceable to TAJ APPS, not anonymous.
community.abuse.ch/u/tajapps →