{
  "type": "Domain",
  "indicator": "api.cloudapi.stream",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/api.cloudapi.stream",
    "alexa": "http://www.alexa.com/siteinfo/api.cloudapi.stream",
    "indicator": "api.cloudapi.stream",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {},
    "pulse_info": {
      "count": 0,
      "pulses": [],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 1,
  "pulses": [
    {
      "id": "69de5f631a2f4bca81392ccd",
      "name": "108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure",
      "description": "A coordinated campaign of 108 malicious Chrome extensions operated through shared command-and-control infrastructure at cloudapi[.]stream has been identified, collectively accounting for approximately 20,000 installations. The campaign spans multiple threat categories: 54 extensions steal Google account identities via OAuth2, one extension actively exfiltrates Telegram Web sessions every 15 seconds, and 45 extensions contain a universal backdoor enabling arbitrary URL execution on browser startup. Published under five distinct publisher identities (Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt), these extensions masquerade as legitimate tools including Telegram sidebar clients, slot games, YouTube and TikTok enhancers, and translation utilities. All extensions route stolen credentials, user identities, and browsing data to servers controlled by the same operator, with infrastructure confirming a Malware-as-a-Service business model.",
      "author_name": "AlienVault",
      "modified": "2026-04-14T15:41:27.263000",
      "created": "2026-04-14T15:38:11.151000",
      "revision": 3,
      "tlp": "white",
      "public": 1,
      "adversary": "",
      "indicators": [
        {
          "id": 2798374309,
          "indicator": "profile.name",
          "type": "domain",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 3238517027,
          "indicator": "message.data",
          "type": "domain",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 3936588044,
          "indicator": "chrome.runtime.id",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 3960785432,
          "indicator": "cloudapi.stream",
          "type": "domain",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 3960785432,
          "indicator": "cloudapi.stream",
          "type": "domain",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 3960807628,
          "indicator": "crm.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 3960807630,
          "indicator": "multiaccount.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278187,
          "indicator": "144.126.135.238",
          "type": "IPv4",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": "2026-05-14T15:00:00",
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278189,
          "indicator": "http://api.cloudapi.stream:8443/Register",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278190,
          "indicator": "http://api.cloudapi.stream:8443/Translation",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278191,
          "indicator": "http://cloudapi.stream/install/",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278192,
          "indicator": "http://cloudapi.stream/uninstall/",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278193,
          "indicator": "http://mines.cloudapi.stream/auth_google",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278194,
          "indicator": "http://mines.cloudapi.stream/slot_test/",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278195,
          "indicator": "http://mines.cloudapi.stream/user_info",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278198,
          "indicator": "http://tg.cloudapi.stream/count_sessions.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278199,
          "indicator": "http://tg.cloudapi.stream/delete_session.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278200,
          "indicator": "http://tg.cloudapi.stream/get_session.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278201,
          "indicator": "http://tg.cloudapi.stream/get_sessions.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278202,
          "indicator": "http://tg.cloudapi.stream/save_session.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278203,
          "indicator": "http://tg.cloudapi.stream/save_title.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278204,
          "indicator": "http://top.rodeo/notify.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278205,
          "indicator": "http://top.rodeo/server/remote.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278206,
          "indicator": "http://top.rodeo/server/remote3.php",
          "type": "URL",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278216,
          "indicator": "interalt.net",
          "type": "domain",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278217,
          "indicator": "nashprom.info",
          "type": "domain",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278218,
          "indicator": "profile.email",
          "type": "domain",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278219,
          "indicator": "webuk.tech",
          "type": "domain",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278220,
          "indicator": "support@top.rodeo",
          "type": "email",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278221,
          "indicator": "api.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278221,
          "indicator": "api.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278222,
          "indicator": "cdn.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278223,
          "indicator": "chat.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278224,
          "indicator": "coin-miner.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278225,
          "indicator": "gamewss.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278226,
          "indicator": "goldminer.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278227,
          "indicator": "herculessportslegend.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278228,
          "indicator": "metal.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278229,
          "indicator": "mines.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278229,
          "indicator": "mines.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278230,
          "indicator": "tg.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:40:56",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278230,
          "indicator": "tg.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278231,
          "indicator": "topup.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4310278232,
          "indicator": "wheel.cloudapi.stream",
          "type": "hostname",
          "created": "2026-04-14T15:38:11",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        }
      ],
      "tags": [
        "session hijacking",
        "chrome extensions",
        "google identity theft",
        "browser backdoor"
      ],
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        "T1113",
        "T1056.001",
        "T1059.007",
        "T1539",
        "T1074.001",
        "T1204.002",
        "T1176",
        "T1005",
        "T1140",
        "T1567",
        "T1219",
        "T1185",
        "T1102",
        "T1528",
        "T1041",
        "T1566",
        "T1027",
        "T1573",
        "T1071.001",
        "T1105"
      ],
      "references": [
        "https://socket.dev/blog/108-chrome-ext-linked-to-data-exfil-session-theft-shared-c2"
      ],
      "industries": [],
      "extract_source": [],
      "more_indicators": false,
      "indicator_count": 44
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "api.cloudapi.stream",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "api.cloudapi.stream",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776209535.0784607
}