api.cloudsettle.org/ws/tunnel/

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:43:46

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
104.26.0.234, 104.26.1.234, 172.67.68.251
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
CloudSettle Tunnel RAT (provisional) 6d0282f31c8a… C2 2026-09-20
CloudSettle Tunnel RAT (provisional) 6e562f3028b5… C2 2026-10-04
CloudSettle Tunnel RAT (provisional) 48bf67f14bd6… C2 2026-10-05
CloudSettle Tunnel RAT (provisional) 86b4dcd83121… C2 2026-10-08
CloudSettle Tunnel RAT (provisional) 2927b3f980c7… C2 2026-10-10

About CloudSettle Tunnel RAT (provisional)

India-targeted, heavily packed Android banking RAT. The real payload is recovered only after a five-layer native unpack chain (header XOR, a 4-pass-KSA RC4, AES-256-GCM with a key built by XORing two hardcoded arrays, zlib inflate, then a bundle format) guarded by certificate-pinning anti-tamper. It establishes a control tunnel over WebSocket to wss://api.cloudsettle.org/ws/tunnel/ with an https://api.cloudsettle.org fallback. Family label provisional. '

Signing certificate

Subject CN
HappyByte Labs
Issuer CN
HappyByte Labs
Valid
2026-10-04 → 2057-09-13
Fingerprint
23a9ed597362579e8258f031fa5afaa759e5e8f866ef7a80d1b4e393a662e8d1

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.