logo

CloudEyE MaaS Downloader and Cryptor Infects Over 100,000 Users Globally

ID: 01bf102c-22ce-5506-8323-39ab3a575ad3

STIX ID: report--01bf102c-22ce-5506-8323-39ab3a575ad3

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ESET Research reports a significant surge in CloudEyE activity—an obfuscated Malware-as-a-Service downloader/cryptor linked to over 100,000 infection attempts in H2 2025—that uses PowerShell, JavaScript and NSIS vectors to deliver secondary payloads (e.g., Formbook, Agent Tesla), with concentrated targeting in Central and Eastern Europe and implications for endpoint and email defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.