api.cloudsettle.org/ws/tunnel/
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:43:46
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 104.26.0.234, 104.26.1.234, 172.67.68.251
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| CloudSettle Tunnel RAT (provisional) | 6d0282f31c8a… | C2 | 2026-09-20 |
| CloudSettle Tunnel RAT (provisional) | 6e562f3028b5… | C2 | 2026-10-04 |
| CloudSettle Tunnel RAT (provisional) | 48bf67f14bd6… | C2 | 2026-10-05 |
| CloudSettle Tunnel RAT (provisional) | 86b4dcd83121… | C2 | 2026-10-08 |
| CloudSettle Tunnel RAT (provisional) | 2927b3f980c7… | C2 | 2026-10-10 |
About CloudSettle Tunnel RAT (provisional)
India-targeted, heavily packed Android banking RAT. The real payload is recovered only after a five-layer native unpack chain (header XOR, a 4-pass-KSA RC4, AES-256-GCM with a key built by XORing two hardcoded arrays, zlib inflate, then a bundle format) guarded by certificate-pinning anti-tamper. It establishes a control tunnel over WebSocket to wss://api.cloudsettle.org/ws/tunnel/ with an https://api.cloudsettle.org fallback. Family label provisional. '
Signing certificate
- Subject CN
- HappyByte Labs
- Issuer CN
- HappyByte Labs
- Valid
- 2026-10-04 → 2057-09-13
- Fingerprint
- 23a9ed597362579e8258f031fa5afaa759e5e8f866ef7a80d1b4e393a662e8d1
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.