logo

New APT Group "CloudSorcerer" Targets Russian Government Entities

ID: 9a8f20f4-c215-590d-bf2b-0b5a3d90245b

STIX ID: report--9a8f20f4-c215-590d-bf2b-0b5a3d90245b

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-07-08

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Kaspersky discovered a sophisticated APT tracked as CloudSorcerer targeting Russian government entities with a C-based backdoor that dynamically adapts behavior by process context and uses cloud platforms (Microsoft Graph, Yandex Cloud, Dropbox, GitHub and others) as C2 and exfiltration channels; Proofpoint later observed a similar spear-phishing campaign (UNK_ArbitraryAcrobat) targeting a U.S. organization using LNK-laden ZIP lures and hex-encoded blobs tied to the same infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.