libalphasdk.so is a malicious native library identified in compromised SmartTube Android app releases for smart TVs and set-top boxes. Reverse-engineering of SmartTube version 30.51 found the hidden library embedded in the APK even though it was not present in the public open-source code, indicating it was likely injected during the release build process after the app’s signing key was leaked. Investigators reported the library had been present since SmartTube version 30.27, suggesting the compromise began roughly one month before discovery. The library reportedly runs in the background without user consent and periodically collects and transmits data over an encrypted communication channel. At the time of reporting, no DDoS botnet behavior or other additional malicious activity had been observed, though the library was assessed as capable of enabling harmful functionality in the future. The activity is associated with the SmartTube supply-chain/signing-key compromise rather than a named threat actor. Affected targets are SmartTube users on Android-based smart TVs and set-top boxes. Reported indicators related to the incident include MD5 hashes 0ba2cc482828aff5eab9dcfd66b769e3, 0c3bec3debae6bfba4104748beabdb56, 0ee8e0f0cb8db222ee021a1da9f26f40, 1c14f2a92b25a67b32eb5d67670f2f32, and 24b6611ee3f6ffefa2e830bb858e015c.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
libalphasdk.so is a malicious library embedded in certain versions of the SmartTube Android app. It operates in the background without user consent, periodically collecting and exfiltrating data via encrypted channels. While no overtly malicious activities like DDoS have been observed, the library poses a risk of future activation of such features.
libalphasdk.so is a malicious native library injected into compromised SmartTube APKs. It fingerprints the host device, registers it with a remote backend, and periodically sends metrics and retrieves configuration via an encrypted channel, all without user interaction or visible indication.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.