TajApps · Privara
Capability Report · Malware analysis

Privara Unmask: detonation & C2‑recovery results.

An honest measurement of what our automated Android malware‑analysis engine recovers — and, just as importantly, where it doesn't yet. Every indicator below is either independently corroborated against public threat intelligence or contributed to the abuse.ch ThreatFox community feed.

Prepared by TAJ APPS LLC · Date 9 September 2026 · Corpus source MalwareBazaar (abuse.ch) · Scope Android banking trojans & RATs
15
Android malware families tested
13
With command‑and‑control recovered
87%
C2 recovery rate
4
Independently corroborate public ground truth
13 recovered 2 coverage tail (documented, never misreported)

How we test

Real samples, sourced from MalwareBazaar, detonated on a de‑emulated Android 17 device that anti‑analysis code can't fingerprint as virtual.

Each sample runs in an isolated, per‑sample environment. Privara Unmask drives it past its activation gates (accessibility, locale, target‑app, SMS/OTP and push triggers), unpacks packed and dropper stages, and recovers command‑and‑control and indicators from what the running sample reveals. We publish a C2 only when the evidence backs it, distinguish a recovered identity from a live beacon, and remove shared or benign infrastructure rather than inflate the count. We do not disclose how the de‑emulation itself is built.

Command‑and‑control recovered — 13 families

"Corroborated" = our recovery independently matches infrastructure already documented by abuse.ch or a named vendor (validation against ground truth). "Contributed" = intelligence we submitted to the ThreatFox community feed.

FamilyRecovered C2 (example)Verification
HookOverlay banker / RAThrjob‑forward‑build.storeCorroborated
ERMACOverlay banker193.222.96.48:3434Corroborated
CerberusPacked banker217.8.117.30:80Corroborated
BrokewellDevice‑takeover bankermi6.operationanonrecoil.ruCorroborated
TrickMoAccessibility bankerbtceducationcenter.comContributed
GodfatherOn‑device‑fraud bankerTelegram dead‑drop channelsContributed
BingoModOn‑device‑fraud RAT23.254.226.46:8055 · :13500Contributed
SoumniBotManifest‑obfuscated banker54.162.26.208:29221 · MQTT :1883Contributed
Coper / OctoTarget‑app‑gated banker5 × .shop C2 domainsContributed
FluhorseCredential / 2FA stealerjp.yelove.xyzContributed
MamontLocale‑gated stealer194.41.113.39:8081Contributed
Anubis‑familyPacked a11y dropperjsonserv.biz/app‑storeContributed
mParivahan‑familyFirebase‑C2 dropperFirebase RTDB endpointRecovered

What we don't over‑claim — 2 families

A sandbox that finds something in everything is worse than one that says when it didn't. These are documented honestly as the current coverage tail — never reported as findings.

FamilyOutcomeWhy — and what it is, not
VulturVNC bankerDid not detonateDid not execute its payload in this environment across two attempts; a per‑run outcome and a retry candidate — not a confirmed clean verdict.
SpyNoteGeneric RATDid not detonateAs above — did not execute this run; flagged for re‑detonation, not misreported as benign.
On the roadmap, stated plainly. A separate no‑warm‑process dropper case needs offline payload decryption we're still building, and the two families above are re‑detonation / infrastructure‑liveness cases. Privara Unmask is early and improving deliberately — we'd rather show you the true rate than a rounded‑up one.

Verify it yourself

This isn't a claim — the intelligence is public and checkable.

Per‑family threat research

Full write‑ups for each recovered family, with recovered indicators, MITRE ATT&CK mapping and cited sources.

tajapps.com/research →

Contributed to abuse.ch ThreatFox

Indicators submitted under our verified community account — traceable to TAJ APPS, not anonymous.

community.abuse.ch/u/tajapps →

Where the honest limit sits