CloudSorcerer hackers abuse cloud services to steal Russian govt data

Share:

A new advanced persistent threat (APT) group named CloudSorcerer abuses public cloud services to steal data from Russian government organizations in cyberespionage attacks.

Kaspersky security researchers discovered the cyberespionage group in May 2024. They report that CloudSorcerer uses custom malware that uses legitimate cloud services for command and control (C2) operations and data storage.

Kaspersky notes that CloudSorcerer’s modus operandi is similar to CloudWizard APT’s, but their malware is distinct, leading security researchers to believe this is a new threat actor.

CloudSorcerer malware details

While Kaspersky does not explain how the threat actors initially breach a network, they say they execute the custom Windows backdoor manually.

The malware has a process-specific behavior depending on where it has been injected, which it determines using ‘GetModuleFileNameA.’

If executed from within “mspaint.exe,” it acts as a backdoor, collecting data and executing code. However, if it is launched within “msiexec.exe,” it first initiates C2 communication to receive commands to execute.

The initial communication is a request to a GitHub repository (up at the time of writing) that contains a hexadecimal string that determines which cloud service to use for further C2 operations: Microsoft Graph, Yandex Cloud, or Dropbox.

For processes that don’t match any hardcoded behavior, the malware injects shellcode into the MSIexec, MSPaint, or Explorer process and terminates the initial process.

The shellcode parses the Process Environment Block (PEB) to identify Windows core DLL offsets, identifies required Windows APIs using the ROR14 algorithm, and maps the CloudSorcerer code into the memory of targeted processes.

Data exchange between modules is organized through Windows pipes for seamless inter-process communication.

The backdoor module, which performs the data theft, collects system information such as computer name, user name, Windows subversion, and system uptime.

It also supports a range of commands retrieved from the C2, including:

  • Shell command execution using the ‘ShellExecuteExW’ API
  • Copy, move, rename, or delete files
  • Receive a shellcode from the pipe and inject it into any process by allocating memory and creating a new thread in a remote process
  • Receive a PE file, create a section, and map it into the remote process
  • Create a process using COM interfaces
  • Create a process as a dedicated user
  • Create a new service or modify an existing service
  • Add new network users or remove legitimate users from the system

Overall, the CloudSorcerer backdoor is a potent tool that enables the threat actors to perform malicious actions on the infected machines.

Kaspersky characterizes the CloudSorcerer attacks as highly sophisticated due to the malware’s dynamic adaptation and covert data communication mechanisms.

Indicators of compromise (IoC) and Yara rules for detecting the CloudSorcerer malware are available at the bottom of Kaspersky’s report.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:30 pm, Jan 19, 2025
weather icon 3°C
L: 2° | H: 4°
overcast clouds
Humidity: 83 %
Pressure: 1019 mb
Wind: 5 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:55 am
Sunset: 4:26 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
2° | 4°°C 0 mm 0% 3 mph 83 % 1019 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 4 mph 92 % 1019 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 95 % 1017 mb 0 mm/h
Wed Jan 22 9:00 pm
weather icon
4° | 5°°C 1 mm 100% 4 mph 98 % 1010 mb 0 mm/h
Thu Jan 23 9:00 pm
weather icon
3° | 6°°C 1 mm 100% 13 mph 92 % 1003 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 4°°C 0 mm 0% 3 mph 83 % 1019 mb 0 mm/h
Today 9:00 pm
weather icon
3° | 4°°C 0 mm 0% 3 mph 78 % 1019 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 4°°C 0 mm 0% 2 mph 75 % 1019 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 2 mph 74 % 1019 mb 0 mm/h
Tomorrow 6:00 am
weather icon
4° | 4°°C 0 mm 0% 2 mph 75 % 1019 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0 mm 0% 2 mph 76 % 1019 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
5° | 5°°C 0 mm 0% 4 mph 84 % 1019 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 4 mph 79 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,822.80
0.77%
Ethereum(ETH)
€3,308.53
3.93%
XRP(XRP)
€3.05
-1.19%
Tether(USDT)
€0.97
-0.02%
Solana(SOL)
€259.73
6.45%
Dogecoin(DOGE)
€0.378684
-0.73%
USDC(USDC)
€0.97
0.01%
Shiba Inu(SHIB)
€0.000021
-4.49%
Pepe(PEPE)
€0.000017
-5.92%
Peanut the Squirrel(PNUT)
€0.448956
-11.70%
Scroll to Top