PULSE NAME
Canis C2 Exposed: Previously Undocumented Cross-Platform ...
WHITE AlienVault 2026-04-08 Modified: 2026-04-09
12
IOCs
MEDIUM VOLUME
On March 19, a researcher on X posted a suspicious Android APK tied to a phishing page impersonating Paidy, a Japanese buy-now-pay-later service. A quick look at the infrastructure behind it revealed an unauthenticated API sitting wide open, with endpoints exposing payloads, command logs, and the C2 source code itself. The server wasn't running a simple credential harvester. Agents for Android, iOS, Windows, Linux, and macOS were present, alongside a canvas-based device fingerprinting system and code that references iOS sandboxing mechanisms by name. The actor behind it is clearly comfortable with Japanese, and large portions of the codebase show signs of LLM-assisted development.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (12)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 01813833afbe76f6968b7982528ce783 2026-04-08
FileHash-SHA1 c860bf65930b4bb956c3f7bee999f7a5dcfdb3b3 2026-04-08
FileHash-SHA256 564b381dc3e6fc737fd9b46fb5ee1e06f4e333d2886f0805514af44947a4c271 2026-04-08
FileHash-SHA256 f8e9a720468c89f191d8cb12d46d81ef67b87a9ef95a307835c556a0885bd181 2026-04-08
URL http://info-payeasy.com/assets/index-DdmV8luQ.js 2026-04-08
URL http://info-payeasy.com/pages/overview.html 2026-04-08
domain americanexpress-site.com 2026-04-08
domain android-protect.com 2026-04-08
domain applesecurity.pro 2026-04-08
domain devicesecurity.pro 2026-04-08
domain info-payeasy.com 2026-04-08
domain ios-deviceprotect.com 2026-04-08