CloudEyE MaaS Downloader and Cryptor Infects Over 100,000 Users Globally
ID: 01bf102c-22ce-5506-8323-39ab3a575ad3
STIX ID: report--01bf102c-22ce-5506-8323-39ab3a575ad3
Feed Name: GBHackers
Threat Score
ESET Research reports a significant surge in CloudEyE activity—an obfuscated Malware-as-a-Service downloader/cryptor linked to over 100,000 infection attempts in H2 2025—that uses PowerShell, JavaScript and NSIS vectors to deliver secondary payloads (e.g., Formbook, Agent Tesla), with concentrated targeting in Central and Eastern Europe and implications for endpoint and email defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
