syamrat.syamcloud.com

domain resolving

Tracked by C2 Tracker · Updated as of 2026-10-07 · Whois queried 2026-10-07T13:21:11

Registration

Registrar
—
Registered
—
Expires
—

DNS

Resolves to
203.55.176.60
Nameservers
—
Status
—

Observed in malware

FamilySample SHA-256First seen
SyamRAT (provisional) e9bf1b6ae043… 2026-09-26
SyamRAT (provisional) 3efa80d2a7a1… 2026-09-29
SyamRAT (provisional) 7f9d84dde2ca… 2026-10-03
SyamRAT (provisional) 92e625364ce3… 2026-10-05

About SyamRAT (provisional)

Commodity **Indonesian Android RAT** distributed under utility/"booster" lures (e.g. package `com.pt.sejahtera`, label *"pelancar hp"* — Indonesian for "phone booster"). The build ships a plaintext `assets/config.json` naming the operator backend, and abuses **AccessibilityService** + **MediaProjection** for remote control, overlay injection and live screen capture. A bundled native module (`libnuker.so` / `assets/nuker`, an ELF) provides the screen-stream/VNC component. Live control runs over **Socket.IO** to the `base_url` in the config. How the C2 is recovered: `config.json` is cleartext, so the decoder reads `base_url` directly (binary-verified). The `webview_url` (commonly `https://www.google.com`) and `logo_url` (image CDNs such as catbox.moe) are victim-facing decoys and are **not** recorded as C2. The operator `username`, `session_id` and per-build `uid` (from `assets/uid.json`) are captured as attribution. Family label is provisional — this is a builder kit, not a single actor.

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Valid
2016-10-23 → 2044-03-10
Fingerprint
1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.