New APT Group "CloudSorcerer" Targets Russian Government Entities
ID: 9a8f20f4-c215-590d-bf2b-0b5a3d90245b
STIX ID: report--9a8f20f4-c215-590d-bf2b-0b5a3d90245b
Feed Name: The Hacker News
Kaspersky discovered a sophisticated APT tracked as CloudSorcerer targeting Russian government entities with a C-based backdoor that dynamically adapts behavior by process context and uses cloud platforms (Microsoft Graph, Yandex Cloud, Dropbox, GitHub and others) as C2 and exfiltration channels; Proofpoint later observed a similar spear-phishing campaign (UNK_ArbitraryAcrobat) targeting a U.S. organization using LNK-laden ZIP lures and hex-encoded blobs tied to the same infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
