logo

CloudSorcerer hackers abuse cloud services to steal Russian govt data

ID: daf767a8-05b6-56f4-98d3-cd6d1679914c

STIX ID: report--daf767a8-05b6-56f4-98d3-cd6d1679914c

Feed Name: DataBreaches.Net

Threat Score
74/100

Date Published: 2024-07-08

Date Updated: 2026-04-19

Author: Dissent

...
...

Kaspersky researchers identified a new APT dubbed CloudSorcerer that abuses legitimate public cloud services for command-and-control and data exfiltration in cyberespionage attacks against Russian government organizations, employing custom malware with tactics reminiscent of CloudWizard but distinct tooling ([report](https://securelist.com/cloudsorcerer-new-apt-cloud-actor/113056/) and coverage: https://www.bleepingcomputer.com/news/security/cloudsorcerer-hackers-abuse-cloud-services-to-steal-russian-govt-data/).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.