CloudSorcerer hackers abuse cloud services to steal Russian govt data

Share:

A new advanced persistent threat (APT) group named CloudSorcerer abuses public cloud services to steal data from Russian government organizations in cyberespionage attacks.

Kaspersky security researchers discovered the cyberespionage group in May 2024. They report that CloudSorcerer uses custom malware that uses legitimate cloud services for command and control (C2) operations and data storage.

Kaspersky notes that CloudSorcerer’s modus operandi is similar to CloudWizard APT’s, but their malware is distinct, leading security researchers to believe this is a new threat actor.

CloudSorcerer malware details

While Kaspersky does not explain how the threat actors initially breach a network, they say they execute the custom Windows backdoor manually.

The malware has a process-specific behavior depending on where it has been injected, which it determines using ‘GetModuleFileNameA.’

If executed from within “mspaint.exe,” it acts as a backdoor, collecting data and executing code. However, if it is launched within “msiexec.exe,” it first initiates C2 communication to receive commands to execute.

The initial communication is a request to a GitHub repository (up at the time of writing) that contains a hexadecimal string that determines which cloud service to use for further C2 operations: Microsoft Graph, Yandex Cloud, or Dropbox.

For processes that don’t match any hardcoded behavior, the malware injects shellcode into the MSIexec, MSPaint, or Explorer process and terminates the initial process.

The shellcode parses the Process Environment Block (PEB) to identify Windows core DLL offsets, identifies required Windows APIs using the ROR14 algorithm, and maps the CloudSorcerer code into the memory of targeted processes.

Data exchange between modules is organized through Windows pipes for seamless inter-process communication.

The backdoor module, which performs the data theft, collects system information such as computer name, user name, Windows subversion, and system uptime.

It also supports a range of commands retrieved from the C2, including:

  • Shell command execution using the ‘ShellExecuteExW’ API
  • Copy, move, rename, or delete files
  • Receive a shellcode from the pipe and inject it into any process by allocating memory and creating a new thread in a remote process
  • Receive a PE file, create a section, and map it into the remote process
  • Create a process using COM interfaces
  • Create a process as a dedicated user
  • Create a new service or modify an existing service
  • Add new network users or remove legitimate users from the system

Overall, the CloudSorcerer backdoor is a potent tool that enables the threat actors to perform malicious actions on the infected machines.

Kaspersky characterizes the CloudSorcerer attacks as highly sophisticated due to the malware’s dynamic adaptation and covert data communication mechanisms.

Indicators of compromise (IoC) and Yara rules for detecting the CloudSorcerer malware are available at the bottom of Kaspersky’s report.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:31 am, Jun 1, 2025
weather icon 18°C
L: 17° | H: 19°
overcast clouds
Humidity: 54 %
Pressure: 1014 mb
Wind: 13 mph SSW
Wind Gust: 17 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 19°°C 0 mm 0% 14 mph 70 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 10 mph 82 % 1019 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 17°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
9° | 19°°C 0 mm 0% 13 mph 83 % 1010 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 15°°C 1 mm 100% 13 mph 97 % 1009 mb 0 mm/h
Today 1:00 pm
weather icon
17° | 18°°C 0 mm 0% 12 mph 51 % 1014 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 17°°C 0 mm 0% 14 mph 44 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
15° | 15°°C 0 mm 0% 12 mph 51 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 9 mph 70 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 13°°C 0 mm 0% 7 mph 82 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 7:00 am
weather icon
12° | 12°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 48 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,672.75
0.54%
Ethereum(ETH)
€2,198.77
-1.27%
Tether(USDT)
€0.88
0.01%
XRP(XRP)
€1.89
-0.30%
Solana(SOL)
€133.60
-1.63%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.165765
-0.17%
Shiba Inu(SHIB)
€0.000011
1.80%
Pepe(PEPE)
€0.000010
0.96%
Peanut the Squirrel(PNUT)
€0.226834
2.40%
Scroll to Top