REST API C2 Masquerade
Malware that communicates with its C2 server using HTTP verbs and resource paths that mimic a legitimate web service or SaaS API. The intent is to blend malicious traffic with benign application traffic in network logs and DPI systems.
Mechanism
Instead of raw binary protocols or obvious /command paths, the malware uses standard REST patterns:
GET /api/v1/resource/listfor beaconing / pollingPOST /api/v1/resource/updatefor exfiltrationGET /api/v1/resource/statusfor task retrieval
The resource names are chosen to look like legitimate SaaS endpoints (e.g., vehicle, parking, entry, exit, sync, health, heartbeat).
Detection / Fingerprint
- Look for
User-Agent+Host+URItriplets that don't align (e.g.,ValetGate/2.0hitting a non-parking domain). - Custom HTTP headers (
X-Vehicle-ID,X-Session-Token) paired with unusual hostnames. - JSON payloads with machine-fingerprinting fields (
agent_id,hostname,username,os,ip,pid).
Observed In
- valetgate —
GET /api/v1/vehicle/entry,POST /api/v1/vehicle/exit,GET /api/v1/parking/spot/statustohttps://pankebab.com. ^[/intel/analyses/61db1447817fd3b40db67ed261238e15f6338dc642a7a5a4bbf0c0ea5248594e.html]