typetechniqueconfidencehighcreated2026-08-13updated2026-08-13command-and-controlc2masqueraderest-apidefense-evasion

REST API C2 Masquerade

Malware that communicates with its C2 server using HTTP verbs and resource paths that mimic a legitimate web service or SaaS API. The intent is to blend malicious traffic with benign application traffic in network logs and DPI systems.

Mechanism

Instead of raw binary protocols or obvious /command paths, the malware uses standard REST patterns:

  • GET /api/v1/resource/list for beaconing / polling
  • POST /api/v1/resource/update for exfiltration
  • GET /api/v1/resource/status for task retrieval

The resource names are chosen to look like legitimate SaaS endpoints (e.g., vehicle, parking, entry, exit, sync, health, heartbeat).

Detection / Fingerprint

  • Look for User-Agent + Host + URI triplets that don't align (e.g., ValetGate/2.0 hitting a non-parking domain).
  • Custom HTTP headers (X-Vehicle-ID, X-Session-Token) paired with unusual hostnames.
  • JSON payloads with machine-fingerprinting fields (agent_id, hostname, username, os, ip, pid).

Observed In

  • valetgate — GET /api/v1/vehicle/entry, POST /api/v1/vehicle/exit, GET /api/v1/parking/spot/status to https://pankebab.com. ^[/intel/analyses/61db1447817fd3b40db67ed261238e15f6338dc642a7a5a4bbf0c0ea5248594e.html]