CloudSorcerer is a likely new APT targeting Russian government entities with stealthy cloud-native cyber espionage operations.
Analyst brief
CloudSorcerer is a likely new sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealthy operations. It leverages cloud APIs and authentication tokens, with GitHub serving as its initial C2 server, for monitoring and data exfiltration. Core TTPs include modular execution based on the host process, complex inter-process communication via Windows pipes, and cloud-native C2 mechanisms inspired by the CloudWizard APT. Defenders should monitor for anomalous cloud API usage, especially towards GitHub, token-based authentication activities, and suspicious Windows pipe communications, while staying vigilant for TTPs overlapping with CloudWizard.
CloudSorcerer
unknown
CloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The malware leverages APIs and authentication tokens to access cloud resources for command and control, with GitHub serving as its initial C2 server. CloudSorcerer operates as separate modules depending on the process it's running in, executing from a single executable and utilizing complex inter-process communication through Windows pipes. The actor behind CloudSorcerer shows similarities to the CloudWizard APT in modus operandi, but the unique code and functionality suggest it is a new threat actor inspired by previous techniques.