CloudScout: Evasive Panda scouting cloud services
ID: 15a14f9b-f98d-57d9-bcdb-b5319d453613
STIX ID: report--15a14f9b-f98d-57d9-bcdb-b5319d453613
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
This ESET blogpost analyzes CloudScout, a modular .NET toolset used by the China-aligned APT Evasive Panda to exfiltrate data from cloud services by stealing browser session cookies and executing C# modules (CGD/CGM/COL) deployed via MgBot plugins; it documents technical module behavior, development artifacts, victimology (Taiwan government and a religious organization), IoCs, and mapped ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
