852f692cdfd4c9b3578232ed…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

CloudSettle Tunnel RAT (provisional). CloudSettle Tunnel RAT (provisional) is an India-targeted Android banking/phishing RAT delivered by a per-build native dropper. The real payload is hidden in an encrypted asset and only runs after a multi-stage unpack.

What it does

  • Fake “NxtGen mParivahan” RTO e-challan and wedding-invitation lures (Wedding-Ceremoney / शुभ विवाहः / Vivah Utsav).
  • Installs a second-stage app via a fake Google Play update screen, then runs a Rs 1 “Verification Fee” UPI-PIN and card-phishing flow.
  • Steals and sends SMS, captures PINs via accessibility overlays, and opens a WebSocket reverse tunnel.

How the payload is unpacked (binary-only)

  • A per-build renamed native lib (ndsSV) decrypts the asset: 16-byte XOR, then 4-pass-KSA RC4, then AES-256-GCM (key = two dex byte[32] arrays XOR’d), then a zlib MSZ1 / MSP1 bundle = base.apk (empty classes.dex) + split_config.dex.apk (the RAT).
  • Recovered in-house with AES-GCM MAC validation on all six samples.

C2 and backend

  • Control channel wss://api.cloudsettle.org/ws/tunnel/device-b (https://api.cloudsettle.org API base for /register, /save-pin, /save-card, /sms/*).
  • This is the embedded default only: Firebase Remote Config keys base_url / tunnel_ws_url can rotate it at runtime.
  • Firebase project andromeda-d389d (FCM topic all_devices) is the command/config backend, a more durable channel than the domain.
  • All six samples share project andromeda-d389d; the two mParivahan lures share app id ...53c99731, the four wedding lures ...75b2e2.

Family label provisional. Indicators: wss://api.cloudsettle.org/ws/tunnel/device-b, https://andromeda-d389d.firebasestorage.app.

Recovered configuration

aes_key
084631c59bd7428097a45f6956f74c9fcd2eb2afc314508ada6651bcb45c92a8
app_label
NxtGen mParivahan
base_apk_dex
empty (code in split_config.dex.apk)
c2_default_firebase_rotatable
True
c2_http_api_base
https://api.cloudsettle.org
firebase
{'project': 'andromeda-d389d', 'sender_number': '651390976306', 'app_id': '1:651390976306:android:53c99731aa157ea66f972b', 'api_key': 'AIzaSyBMHTORCrdpWwTBah5Lrid3iGP8hJuBnbI', 'storage_bucket': 'andromeda-d389d.firebasestorage.app', 'fcm_topic': 'all_devices'}
package
com.telenor.android.provider.yvq15o07
packer
native renamed-lib dropper (XOR16 -> 4-pass-KSA RC4 -> AES-256-GCM(two dex byte[32] XOR) -> zlib MSZ1 -> MSP1)
remote_config_override_keys
base_url, tunnel_ws_url

Identification

SHA-256
852f692cdfd4c9b3578232ed19073377e728bf7ad7d7c7cc979ff9f865210e93
MD5
a7fe1fcf1f533bae3ec4e4858b970426

Observed

Families
CloudSettle Tunnel RAT (provisional)
First seen
2026-10-10

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
andromeda-d389d.firebasestorage.app domain - https CloudSettle Tunnel RAT (provisional) 2026-10-10
api.cloudsettle.org/ws/tunnel/device-b domain - wss CloudSettle Tunnel RAT (provisional) 2026-10-10

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About CloudSettle Tunnel RAT (provisional)

**CloudSettle Tunnel RAT (provisional)** is an India-targeted Android banking/phishing RAT delivered by a per-build native dropper. The real payload is hidden in an encrypted asset and only runs after a multi-stage unpack. **What it does** - Fake **"NxtGen mParivahan"** RTO e-challan and **wedding-invitation** lures (`Wedding-Ceremoney` / `शुभ विवाहः` / `Vivah Utsav`). - Installs a second-stage app via a fake Google Play update screen, then runs a Rs 1 **"Verification Fee"** UPI-PIN and card-phishing flow. - Steals and sends SMS, captures PINs via accessibility overlays, and opens a **WebSocket reverse tunnel**. **How the payload is unpacked (binary-only)** - A per-build renamed native lib (`ndsSV`) decrypts the asset: 16-byte XOR, then 4-pass-KSA RC4, then AES-256-GCM (key = two dex `byte[32]` arrays XOR'd), then a zlib `MSZ1` / `MSP1` bundle = `base.apk` (empty `classes.dex`) + `split_config.dex.apk` (the RAT). - Recovered in-house with AES-GCM MAC validation on all six samples. **C2 and backend** - Control channel `wss://api.cloudsettle.org/ws/tunnel/device-b` (`https://api.cloudsettle.org` API base for `/register`, `/save-pin`, `/save-card`, `/sms/*`). - This is the embedded **default only**: Firebase Remote Config keys `base_url` / `tunnel_ws_url` can rotate it at runtime. - Firebase project **`andromeda-d389d`** (FCM topic `all_devices`) is the command/config backend, a more durable channel than the domain. - All six samples share project `andromeda-d389d`; the two mParivahan lures share app id `...53c99731`, the four wedding lures `...75b2e2`. Family label provisional.