logo

CloudSorcerer hackers abuse cloud services to steal Russian govt data

ID: 9750ffc5-e291-506e-b731-71d8f06a7845

STIX ID: report--9750ffc5-e291-506e-b731-71d8f06a7845

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-07-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CloudSorcerer is a newly identified APT that uses a custom Windows backdoor and legitimate cloud services for C2 and data exfiltration against Russian government organizations; the malware performs process-specific injection, memory mapping, shellcode injection, and supports extensive remote commands, with IoCs and YARA rules provided by Kaspersky.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.