Canis C2 Surveillance Framework Targets Japan with Phishing Campaign

Canis C2 Surveillance Framework Targets Japan with Phishing Campaign

First seen 13 Apr 2026, 18:00 UTC Technaduhunt.ioprojectzero.google 86% similarity 71.5

Article Content

Browse articles
ThreatCluster

A previously undocumented surveillance framework, Canis C2, has been identified targeting Japan. The investigation began when researchers discovered a phishing Android application masquerading as Paidy, a buy-now-pay-later service. This app led to an exposed backend API, revealing extensive capabilities including location tracking, media access, credential overlay injection, and arbitrary code execution. The malware is designed for multiple platforms, including Android, iOS, Windows, Linux, and macOS. Attackers utilized deceptive phishing tactics, presenting victims with fake electric billing statements to install the malicious application. The framework demonstrates advanced technical sophistication, with signs of LLM-assisted development in its codebase. A campaign identifier, CANIS_2026_FEB, has been linked to this activity. Users are advised to avoid unofficial applications and be cautious of suspicious emails.

Key Points: • Canis C2 framework targets multiple platforms including Android, iOS, and Windows. • Initial access was gained through a phishing app impersonating a legitimate service. • The malware allows extensive permissions, including GPS tracking and media capture.

ThreatCluster AI

Timeline

2026-03-19
Phishing Android APK discovered targeting Paidy service.
2026-03-19
Exposed backend API of Canis C2 framework identified.
2026-04-13
Hunt.io and Technadu publish findings on Canis C2.

Community

Browse all →