La tua posizione Home  :: Libreria articoli :: CyberSecurity :: Threat Actors -> CloudSorcerer

 
      Menu principale
  Home
      About: Totocellux
      LinkedIn
      X (Twitter)
      GitHub
  Libreria articoli
      Avvisi Portale
      Software
      Hardware
      CyberSecurity
      Networking
      Telefonia
      Virtualizzazione
  Galleria Web
  Forum

Benvenuto Ospite, nel Portale Campolo.eu:
se sei già utente effettua il login,
altrimenti puoi facilmente registrarti.

[Registrati] [Login]

      Skin
Seleziona la skin dell'interfaccia

      Moduli
XML - Risorsa di notizie
Consiglia Campolo.eu ai tuoi amici

      Sondaggio settimanale
What do you think of Phoenix?
 
Creative AND Clean
Creative NOT Clean
NOT Creative BUT Clean
NOT (Creative AND Clean)

      CloudSorcerer
espandi info/opzioni dell'articolo | Opzioni articolo | Sommario |
Names CloudSorcerer (Kaspersky) Country [Unknown] Motivation Information theft and espionage First seen 2024 Description (Kaspersky) In May 2024, we discovered a new advanced persistent threat (APT) targeting Russian government entities that we dubbed CloudSorcerer. It’s a sophisticated cyberespionage tool used for stealth monitoring, data collection, and exfiltration via Microsoft Graph, Yandex Cloud, and Dropbox cloud infrastructure. The malware leverages cloud resources as its command and control (C2) servers, accessing them through APIs using authentication tokens. Additionally, CloudSorcerer uses GitHub as its initial C2 server. CloudSorcerer’s modus operandi is reminiscent of the CloudWizard APT (Bad Magic, RedStinger) that we reported on in 2023. However, the malware code is completely different. We presume that CloudSorcerer is a new actor that has adopted a similar method of interacting with public cloud services. Observed Sectors: Government. Countries: Russia. Tools used GrewApacha, PlugY, The CloudSorcerer. Operations performed Jul 2024 Operation “EastWind” EastWind campaign: new CloudSorcerer attacks on government organizations in Russia Information Last change to this card: 27 August 2024
 
Home 

 
      Statistiche del Portale
numero di categorie: [ 44 ] / numero di articoli: [ 106 ]
Numero di collaboratori registrati localmente: [ 4 ]
Numero di accessi unici: [ 728 ]

 
This site is Phoenix Technology Enabled tempo di generazione pagina: [0.035156] secondi
Si consiglia l'uso del browser Google Chrome!!
Powered by Phoenix (UglySabiSkinner)
:: Informativa privacy/cookies ::
Contatta l'Amministratore