Here is my first blog post of 2025. Have a great year!

Sample Details:

SHA256 Hash: 7899ea0aa36bacb8d2f94907373e550cec71d02701107cb2ef3cf629c305f877

Package Name: com.errorforcode.netix

Application Name: بسته معیشت

Analysis

This app also has a Firebase Cloud Messaging Service and Receiver that acts as a listener for the attacker to send commands to the device.

Conclusion

This was an intersting sample to analyze. This was also the first time seeing Messages and Cloud FCM functionality to send attacker commands. I had a lot of fun analyzing this sample.

GG’s <3