'CloudSorcerer' Leverages Cloud Services in Cyber-Espionage Campaign
ID: 1194247a-9806-5013-b88e-2e04341ecf3c
STIX ID: report--1194247a-9806-5013-b88e-2e04341ecf3c
Feed Name: Dark Reading
Threat Score
Kaspersky researchers report a new cyber-espionage actor dubbed “CloudSorcerer” targeting Russian government entities with a single Portable Executable that can operate as distinct data-collection and communication modules, adapt behavior based on the host process (e.g., acting as a backdoor when running in mspaint.exe), and leverage public cloud services (Microsoft Graph API, Dropbox, Yandex Cloud, GitHub) for command-and-control and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
