logo

Inside Canis C2: The ‘Wide Open’ Surveillance Engine Targeting Every Major OS

ID: 0f48a829-f348-5321-937f-fa8184e26e1a

STIX ID: report--0f48a829-f348-5321-937f-fa8184e26e1a

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Hunt.io discovered Canis C2, a sophisticated cross-platform surveillance system whose unauthenticated public API exposed payloads, command logs, and source code; initial detection came from an Android APK impersonating Paidy and operators later moved to a new phishing domain using AitM techniques. The platform targets Android, iOS, Windows, Linux and macOS and supports real-time GPS tracking, camera/microphone capture, credential overlay injection, and persistent remote control, with portions of the codebase showing signs of LLM-assisted development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.