logo

CloudScout: Evasive Panda scouting cloud services

ID: 15a14f9b-f98d-57d9-bcdb-b5319d453613

STIX ID: report--15a14f9b-f98d-57d9-bcdb-b5319d453613

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2024-10-28

Date Updated: 2026-05-01

...
...

This ESET blogpost analyzes CloudScout, a modular .NET toolset used by the China-aligned APT Evasive Panda to exfiltrate data from cloud services by stealing browser session cookies and executing C# modules (CGD/CGM/COL) deployed via MgBot plugins; it documents technical module behavior, development artifacts, victimology (Taiwan government and a religious organization), IoCs, and mapped ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.