← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Canis C2 Exposed: Previously Undocumented Cross-Platform ...
On March 19, a researcher on X posted a suspicious Android APK tied to a phishing page impersonating Paidy, a Japanese buy-now-pay-later service. A quick look at the infrastructure behind it revealed an unauthenticated API sitting wide open, with endpoints exposing payloads, command logs, and the C2 source code itself. The server wasn't running a simple credential harvester. Agents for Android, iOS, Windows, Linux, and macOS were present, alongside a canvas-based device fingerprinting system and code that references iOS sandboxing mechanisms by name. The actor behind it is clearly comfortable with Japanese, and large portions of the codebase show signs of LLM-assisted development.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (12)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 01813833afbe76f6968b7982528ce783 | — | 2026-04-08 | |
| FileHash-SHA1 | c860bf65930b4bb956c3f7bee999f7a5dcfdb3b3 | — | 2026-04-08 | |
| FileHash-SHA256 | 564b381dc3e6fc737fd9b46fb5ee1e06f4e333d2886f0805514af44947a4c271 | — | 2026-04-08 | |
| FileHash-SHA256 | f8e9a720468c89f191d8cb12d46d81ef67b87a9ef95a307835c556a0885bd181 | — | 2026-04-08 | |
| URL | http://info-payeasy.com/assets/index-DdmV8luQ.js | — | 2026-04-08 | |
| URL | http://info-payeasy.com/pages/overview.html | — | 2026-04-08 | |
| domain | americanexpress-site.com | — | 2026-04-08 | |
| domain | android-protect.com | — | 2026-04-08 | |
| domain | applesecurity.pro | — | 2026-04-08 | |
| domain | devicesecurity.pro | — | 2026-04-08 | |
| domain | info-payeasy.com | — | 2026-04-08 | |
| domain | ios-deviceprotect.com | — | 2026-04-08 |