CloudSettle Tunnel RAT (provisional)

Malware family · 5 sample(s) · 5 indicator record(s) · 5 signing certificate(s) · Active 2026-09-20 → 2026-10-10 (experimental)

About CloudSettle Tunnel RAT (provisional)

India-targeted, heavily packed Android banking RAT. The real payload is recovered only after a five-layer native unpack chain (header XOR, a 4-pass-KSA RC4, AES-256-GCM with a key built by XORing two hardcoded arrays, zlib inflate, then a bundle format) guarded by certificate-pinning anti-tamper. It establishes a control tunnel over WebSocket to wss://api.cloudsettle.org/ws/tunnel/ with an https://api.cloudsettle.org fallback. Family label provisional. '

Indicators

IndicatorTypeSampleFirst seen
api.cloudsettle.org/ws/tunnel/ domain 48bf67f14bd6… 2026-10-05
api.cloudsettle.org/ws/tunnel/ domain 6d0282f31c8a… 2026-09-20
api.cloudsettle.org/ws/tunnel/ domain 6e562f3028b5… 2026-10-04
api.cloudsettle.org/ws/tunnel/ domain 86b4dcd83121… 2026-10-08
api.cloudsettle.org/ws/tunnel/device-b domain 2927b3f980c7… 2026-10-10