Pre-installed C2 loader on cheap Android projectors - deploys proxy/ad-fraud botnets, can run arbitrary code
Multiple cheap Android projectors using the Allwinner H713 chipset, sold under various brand names, come pre-installed with a multi-stage malware ecosystem. This malware includes a command-and-control (C2) loader that deploys modular plugins for residential proxy networks, ad-fraud, and botnet activities. The malware has root backdoors and can execute arbitrary code with system privileges. It exfiltrates device identifiers to servers in China and supports geo-fenced malicious activities. The infection chain involves four stages: StoreOS dropper, SilentSDK, PluginManager, and final plugins. Network-level blocking and disabling malicious apps via ADB are recommended mitigations.
AI Analysis
Technical Summary
The threat involves a pre-installed malware ecosystem on cheap Android projectors based on the Allwinner H713 platform, including brands like Nonete HY260Pro and others. The infection chain consists of StoreOS (stage 1 dropper), SilentSDK (stage 2), PluginManager com.me.cash5 (stage 3), and multiple final plugins (stage 4) that enroll devices into residential proxy botnets, ad-fraud schemes, and UDP proxy nodes. The malware communicates with C2 servers such as api.pixelpioneerss.com and others, with infrastructure located in China and Germany. The malware has root backdoors (e.g., open ADB on port 5555) and can execute arbitrary code with system privileges, allowing operators to push any payload. Device identifiers (MAC, serial, Android ID) are exfiltrated. The malware uses obfuscation techniques including byte-reversal, XOR encryption, and build-fingerprint spoofing. Independent confirmation suggests the problem is widespread across multiple brands using the same firmware base. Immediate mitigations include network-level blocking of known C2 domains and IPs and disabling malicious apps via ADB.
Potential Impact
Affected devices are enrolled in multiple botnets and proxy networks, enabling attackers to route traffic through victim devices, conduct ad and click fraud, and potentially deploy arbitrary malicious payloads with root privileges. The malware exfiltrates sensitive device identifiers to servers in China. The presence of open root backdoors and unauthenticated ADB access increases the risk of full device compromise. The geo-fencing capability allows attackers to target specific countries selectively. This compromises device integrity, privacy, and can facilitate broader criminal infrastructure.
Mitigation Recommendations
No official vendor patch is available as this is a supply chain compromise in pre-installed firmware. Immediate mitigations include blocking network traffic to known C2 domains (e.g., api.pixelpioneerss.com, *.aodintech.com, *.syslogcollector.com) and IP addresses associated with the malware at the network perimeter. Users can disable malicious apps using ADB commands to reduce risk. Since the malware operates with root privileges and includes backdoors, replacing the device or firmware with a trusted version is recommended for full remediation.
Pre-installed C2 loader on cheap Android projectors - deploys proxy/ad-fraud botnets, can run arbitrary code
Description
Multiple cheap Android projectors using the Allwinner H713 chipset, sold under various brand names, come pre-installed with a multi-stage malware ecosystem. This malware includes a command-and-control (C2) loader that deploys modular plugins for residential proxy networks, ad-fraud, and botnet activities. The malware has root backdoors and can execute arbitrary code with system privileges. It exfiltrates device identifiers to servers in China and supports geo-fenced malicious activities. The infection chain involves four stages: StoreOS dropper, SilentSDK, PluginManager, and final plugins. Network-level blocking and disabling malicious apps via ADB are recommended mitigations.
Reddit Discussion
Hi everyone,
I recently bought one of those cheap Android projectors (Nonete HY260Pro, Allwinner H713) and noticed some suspicious network activity. Being curious, I decided to set up a lab, intercept the traffic, and dig into the firmware.
I ended up uncovering a factory-installed malware ecosystem: a disguised dropper (StoreOS), a hidden second stage (SilentSDK) and a plugin loader that talks to a C2 server in China (api.pixelpioneerss.com) and deploys up to 5 botnet/fraud plugins.
Key findings of my analysis:
- Four-stage infection chain: StoreOS → SilentSDK → PluginManager → final plugins. Payloads are hidden with a "Byte-Reversal" trick, XOR encryption and build-fingerprint spoofing.
- The plugins currently enroll the device in residential proxy networks (XFJ/net2fast, a UDP proxy node, indicators consistent with the Vo1d botnet) and run ad/click fraud, partly geo-fenced server-side.
- The loader executes downloaded code with system privileges, so the operators can push any payload at any time. I only observed proxy and ad-fraud plugins, but the capability for remote code execution is there by design.
- The device also ships with open root backdoors and sends device identifiers (MAC, serial, Android ID) to servers in China.
- An independent researcher found identical infrastructure on a Magcubic HY300 Pro+, which suggests the problem is the H713 firmware base and not one brand. I could only verify my own device.
This is my first independent technical report and deep dive into malware research. I've documented the full kill chain, decrypted the obfuscated strings, listed IOCs and mitigations (DNS blocklist, ADB disable commands), and written scripts to repair the malformed payloads for analysis.
Full Report: https://github.com/Kavan00/Android-Projector-C2-Malware
I'd love to get your opinion on the report, especially from owners of other H713 devices who can compare.
Looking forward to your feedback!
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat involves a pre-installed malware ecosystem on cheap Android projectors based on the Allwinner H713 platform, including brands like Nonete HY260Pro and others. The infection chain consists of StoreOS (stage 1 dropper), SilentSDK (stage 2), PluginManager com.me.cash5 (stage 3), and multiple final plugins (stage 4) that enroll devices into residential proxy botnets, ad-fraud schemes, and UDP proxy nodes. The malware communicates with C2 servers such as api.pixelpioneerss.com and others, with infrastructure located in China and Germany. The malware has root backdoors (e.g., open ADB on port 5555) and can execute arbitrary code with system privileges, allowing operators to push any payload. Device identifiers (MAC, serial, Android ID) are exfiltrated. The malware uses obfuscation techniques including byte-reversal, XOR encryption, and build-fingerprint spoofing. Independent confirmation suggests the problem is widespread across multiple brands using the same firmware base. Immediate mitigations include network-level blocking of known C2 domains and IPs and disabling malicious apps via ADB.
Potential Impact
Affected devices are enrolled in multiple botnets and proxy networks, enabling attackers to route traffic through victim devices, conduct ad and click fraud, and potentially deploy arbitrary malicious payloads with root privileges. The malware exfiltrates sensitive device identifiers to servers in China. The presence of open root backdoors and unauthenticated ADB access increases the risk of full device compromise. The geo-fencing capability allows attackers to target specific countries selectively. This compromises device integrity, privacy, and can facilitate broader criminal infrastructure.
Defensive Guidance
No official vendor patch is available as this is a supply chain compromise in pre-installed firmware. Immediate mitigations include blocking network traffic to known C2 domains (e.g., api.pixelpioneerss.com, *.aodintech.com, *.syslogcollector.com) and IP addresses associated with the malware at the network perimeter. Users can disable malicious apps using ADB commands to reduce risk. Since the malware operates with root privileges and includes backdoors, replacing the device or firmware with a trusted version is recommended for full remediation.
Technical Details
- Source Type
- Subreddit
- Malware
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:botnet","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["botnet"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ac1071ba43b0b3b89c5906c
Added to database: 10/03/2026, 13:46:03 UTC
Last enriched: 10/03/2026, 13:46:09 UTC
Last updated: 10/04/2026, 04:46:02 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.