Skip to main content

Pre-installed C2 loader on cheap Android projectors - deploys proxy/ad-fraud botnets, can run arbitrary code

0
Medium
Published: 10/03/2026 (10/03/2026, 13:07:02 UTC)
Source: Reddit Malware

Description

Multiple cheap Android projectors using the Allwinner H713 chipset, sold under various brand names, come pre-installed with a multi-stage malware ecosystem. This malware includes a command-and-control (C2) loader that deploys modular plugins for residential proxy networks, ad-fraud, and botnet activities. The malware has root backdoors and can execute arbitrary code with system privileges. It exfiltrates device identifiers to servers in China and supports geo-fenced malicious activities. The infection chain involves four stages: StoreOS dropper, SilentSDK, PluginManager, and final plugins. Network-level blocking and disabling malicious apps via ADB are recommended mitigations.

Reddit Discussion

r/Malware·posted by u/DerErbsenzaehler
00

Hi everyone,

I recently bought one of those cheap Android projectors (Nonete HY260Pro, Allwinner H713) and noticed some suspicious network activity. Being curious, I decided to set up a lab, intercept the traffic, and dig into the firmware.

I ended up uncovering a factory-installed malware ecosystem: a disguised dropper (StoreOS), a hidden second stage (SilentSDK) and a plugin loader that talks to a C2 server in China (api.pixelpioneerss.com) and deploys up to 5 botnet/fraud plugins.

Key findings of my analysis:

  • Four-stage infection chain: StoreOS → SilentSDK → PluginManager → final plugins. Payloads are hidden with a "Byte-Reversal" trick, XOR encryption and build-fingerprint spoofing.
  • The plugins currently enroll the device in residential proxy networks (XFJ/net2fast, a UDP proxy node, indicators consistent with the Vo1d botnet) and run ad/click fraud, partly geo-fenced server-side.
  • The loader executes downloaded code with system privileges, so the operators can push any payload at any time. I only observed proxy and ad-fraud plugins, but the capability for remote code execution is there by design.
  • The device also ships with open root backdoors and sends device identifiers (MAC, serial, Android ID) to servers in China.
  • An independent researcher found identical infrastructure on a Magcubic HY300 Pro+, which suggests the problem is the H713 firmware base and not one brand. I could only verify my own device.

This is my first independent technical report and deep dive into malware research. I've documented the full kill chain, decrypted the obfuscated strings, listed IOCs and mitigations (DNS blocklist, ADB disable commands), and written scripts to repair the malformed payloads for analysis.

Full Report: https://github.com/Kavan00/Android-Projector-C2-Malware

I'd love to get your opinion on the report, especially from owners of other H713 devices who can compare.

Looking forward to your feedback!

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 13:46:09 UTC

Technical Analysis

The threat involves a pre-installed malware ecosystem on cheap Android projectors based on the Allwinner H713 platform, including brands like Nonete HY260Pro and others. The infection chain consists of StoreOS (stage 1 dropper), SilentSDK (stage 2), PluginManager com.me.cash5 (stage 3), and multiple final plugins (stage 4) that enroll devices into residential proxy botnets, ad-fraud schemes, and UDP proxy nodes. The malware communicates with C2 servers such as api.pixelpioneerss.com and others, with infrastructure located in China and Germany. The malware has root backdoors (e.g., open ADB on port 5555) and can execute arbitrary code with system privileges, allowing operators to push any payload. Device identifiers (MAC, serial, Android ID) are exfiltrated. The malware uses obfuscation techniques including byte-reversal, XOR encryption, and build-fingerprint spoofing. Independent confirmation suggests the problem is widespread across multiple brands using the same firmware base. Immediate mitigations include network-level blocking of known C2 domains and IPs and disabling malicious apps via ADB.

Potential Impact

Affected devices are enrolled in multiple botnets and proxy networks, enabling attackers to route traffic through victim devices, conduct ad and click fraud, and potentially deploy arbitrary malicious payloads with root privileges. The malware exfiltrates sensitive device identifiers to servers in China. The presence of open root backdoors and unauthenticated ADB access increases the risk of full device compromise. The geo-fencing capability allows attackers to target specific countries selectively. This compromises device integrity, privacy, and can facilitate broader criminal infrastructure.

Defensive Guidance

No official vendor patch is available as this is a supply chain compromise in pre-installed firmware. Immediate mitigations include blocking network traffic to known C2 domains (e.g., api.pixelpioneerss.com, *.aodintech.com, *.syslogcollector.com) and IP addresses associated with the malware at the network perimeter. Users can disable malicious apps using ADB commands to reduce risk. Since the malware operates with root privileges and includes backdoors, replacing the device or firmware with a trusted version is recommended for full remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
Malware
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:botnet","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["botnet"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6ac1071ba43b0b3b89c5906c

Added to database: 10/03/2026, 13:46:03 UTC

Last enriched: 10/03/2026, 13:46:09 UTC

Last updated: 10/04/2026, 04:46:02 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses