logo

Operation CamelClone: New Global Espionage Campaign Hijacks Public Cloud Tools

ID: ffa37bca-477c-541a-834f-d629f4110d24

STIX ID: report--ffa37bca-477c-541a-834f-d629f4110d24

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ddos

...
...

**Operation CamelClone** is a targeted espionage campaign reported by Seqrite Labs that uses malicious ZIP archives delivering the HOPPINGANT loader to fetch payloads from public file-sharing services and exfiltrate sensitive government and energy-sector data to MEGA via the legitimate Rclone tool; activity has been observed against targets in Algeria, Mongolia, Ukraine, and Kuwait and shows consistent technical fingerprints across incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.