CloudSorcerer – A new APT targeting Russian government entities
ID: 4c96ec82-a9ac-50ab-b915-62d97ee9ca1d
STIX ID: report--4c96ec82-a9ac-50ab-b915-62d97ee9ca1d
Feed Name: Securelist by Kaspersky
Threat Score
This report analyzes CloudSorcerer, a sophisticated APT backdoor discovered in May 2024 targeting Russian government entities; the malware operates as modular code injected into different Windows processes, uses named pipes for IPC, decodes commands via a hardcoded charcode table, and uses GitHub plus public cloud APIs (Microsoft Graph, Yandex Cloud, Dropbox) as C2 infrastructure, with detailed IoCs and MITRE ATT&CK mappings provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
