CloudSettle Tunnel RAT (provisional)
Malware family · 5 sample(s) · 5 indicator record(s) · 5 signing certificate(s) · Active 2026-09-20 → 2026-10-10 (experimental)
About CloudSettle Tunnel RAT (provisional)
India-targeted, heavily packed Android banking RAT. The real payload is recovered only after a five-layer native unpack chain (header XOR, a 4-pass-KSA RC4, AES-256-GCM with a key built by XORing two hardcoded arrays, zlib inflate, then a bundle format) guarded by certificate-pinning anti-tamper. It establishes a control tunnel over WebSocket to wss://api.cloudsettle.org/ws/tunnel/ with an https://api.cloudsettle.org fallback. Family label provisional.
'
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| api.cloudsettle.org/ws/tunnel/ | domain | 48bf67f14bd6… | 2026-10-05 |
| api.cloudsettle.org/ws/tunnel/ | domain | 6d0282f31c8a… | 2026-09-20 |
| api.cloudsettle.org/ws/tunnel/ | domain | 6e562f3028b5… | 2026-10-04 |
| api.cloudsettle.org/ws/tunnel/ | domain | 86b4dcd83121… | 2026-10-08 |
| api.cloudsettle.org/ws/tunnel/device-b | domain | 2927b3f980c7… | 2026-10-10 |