RPRudra Ponksheinblog.realrudrap.dev·Jul 22 · 12 min readSealed with a KYSS: Inside an Android Banking RATAfter wrapping the analysis on my previous sample, another one came in. It called itself KYSS, and the launcher icon was a lipstick-stained kiss mark, the kind of lure which gets people's attention. T11S
RPRudra Ponksheinblog.realrudrap.dev·Jul 14 · 7 min readThe Attacker's DisciplineThere is a specific kind of cognitive dissonance that comes from reverse engineering a malware sample in one terminal while your own app's backend runs in another. I spent the better part of the last 30
RPRudra Ponksheinblog.realrudrap.dev·Jul 8 · 11 min readI Found the Live C2 Server Controlling Thousands of Infected DevicesIf you've been following along, here's where we are: a spam SMS dropped an APK, the APK was a dropper that XOR-decrypted a multi-DEX container, HMAC-validated it, AES-decrypted it, and loaded the resu20
RPRudra Ponksheinblog.realrudrap.dev·Jun 26 · 16 min readThe Media Player that wasn'tContinuing from the first part of the series, where I left off with the DEX file from r_4dfb.bin, it claimed to be a media player. Spoiler alert, it wasn't, and it never was Cracking the container He20
RPRudra Ponksheinblog.realrudrap.dev·Jun 24 · 15 min readThe Spam SMS that turned into a rabbit hole⚠ WARNING: If you received a SMS claiming your vehicle has an outstanding RTO challan with a link which downloads an .apk file, do not open it. This is an active malware campaign as of June 2026 imper20