logo

CloudSorcerer – A new APT targeting Russian government entities

ID: 4c96ec82-a9ac-50ab-b915-62d97ee9ca1d

STIX ID: report--4c96ec82-a9ac-50ab-b915-62d97ee9ca1d

Feed Name: Securelist by Kaspersky

Threat Score
88/100

Date Published: 2024-07-08

Date Updated: 2026-04-29

Author: GReAT

...
...

This report analyzes CloudSorcerer, a sophisticated APT backdoor discovered in May 2024 targeting Russian government entities; the malware operates as modular code injected into different Windows processes, uses named pipes for IPC, decodes commands via a hardcoded charcode table, and uses GitHub plus public cloud APIs (Microsoft Graph, Yandex Cloud, Dropbox) as C2 infrastructure, with detailed IoCs and MITRE ATT&CK mappings provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.