syamrat.syamcloud.com
domainTracked by C2 Tracker · Updated as of 2026-10-07 · Whois queried 2026-10-07T13:21:11
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- 203.55.176.60
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| SyamRAT (provisional) | e9bf1b6ae043… | 2026-09-26 |
| SyamRAT (provisional) | 3efa80d2a7a1… | 2026-09-29 |
| SyamRAT (provisional) | 7f9d84dde2ca… | 2026-10-03 |
| SyamRAT (provisional) | 92e625364ce3… | 2026-10-05 |
About SyamRAT (provisional)
Commodity **Indonesian Android RAT** distributed under utility/"booster" lures (e.g. package `com.pt.sejahtera`, label *"pelancar hp"* — Indonesian for "phone booster"). The build ships a plaintext `assets/config.json` naming the operator backend, and abuses **AccessibilityService** + **MediaProjection** for remote control, overlay injection and live screen capture. A bundled native module (`libnuker.so` / `assets/nuker`, an ELF) provides the screen-stream/VNC component. Live control runs over **Socket.IO** to the `base_url` in the config. How the C2 is recovered: `config.json` is cleartext, so the decoder reads `base_url` directly (binary-verified). The `webview_url` (commonly `https://www.google.com`) and `logo_url` (image CDNs such as catbox.moe) are victim-facing decoys and are **not** recorded as C2. The operator `username`, `session_id` and per-build `uid` (from `assets/uid.json`) are captured as attribution. Family label is provisional — this is a builder kit, not a single actor.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2016-10-23 → 2044-03-10
- Fingerprint
- 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.