Iranian Company Cloudzy Accused of Aiding Cybercriminals and Nation-State Hackers

Teilen:

Services offered by an obscure Iranian company known as Cloudzy are being leveraged by multiple threat actors, including cybercrime groups and nation-state crews.

Although Cloudzy is incorporated in the United States, it almost certainly operates out of Tehran, Iran – in possible violation of U.S. sanctions – under the direction of someone going by the name Hassan Nozari, Halcyon said in a new report published Tuesday.

The Texas-based cybersecurity firm said the company acts as a command-and-control provider (C2P), which provides attackers with Remote Desktop Protocol (RDP) virtual private servers and other anonymized services that ransomware affiliates and others use to pull off the cybercriminal endeavors.

[C2Ps] enjoy a liability loophole that does not require them to ensure that the infrastructure they provide is not being used for illegal operations, Halcyon said in a statement shared with The Hacker News.

The ransomware-as-a-service (RaaS) business model is a highly-evolving one, encompassing the core developers; affiliates, who carry out the attacks in exchange for a cut; and initial access brokers, who exploit known vulnerabilities or stolen credentials to obtain a foothold and sell that access to affiliates.

The emergence of C2P providers points to a new set of actors who knowingly or unwittingly provide the infrastructure to carry out the attacks.

The most unusual thing is how long various attackers operated out of this infrastructure, yet no other security vendor connected the reuse of RDP hostnames to tie them all together, Ryan Smith, Halcyon’s CTO & co-founder, told The Hacker News. Essentially attackers look to automate some of the tedious tasks required for setting up their campaigns, much like every legitimate software company, and by doing so, presumably left themselves open to correlation.

Some of the key actors that are assessed to be leveraging Cloudzy include state-sponsored entities from China (APT10), India (Sidewinder), Iran (APT33 and APT34), North Korea (Kimsuky, Konni, and Lazarus Group), Pakistan (Transparent Tribe), Russia (APT29 and Turla), and Vietnam (OceanLotus) as well as cybercrime entities (Evil Corp and FIN12).

Also in the mix are two ransomware affiliates dubbed Ghost Clown and Space Kook which use the BlackBasta and Royal ransomware strains, respectively, and the controversial Israeli spyware vendor Candiru.

It’s suspected that malicious actors are banking on the fact that purchasing VPS services from Cloudzy only requires a working email address and anonymous payment in cryptocurrency, thus making it ripe for abuse and raising the possibility that threat actors could be weaponizing little-known firms to fuel major hacks.

If your VPS server is suspended because of misuse or abusive usage such as prohibited uses: Phishing, Spamming, Child Porn, Attacking other people, etc., reads the support documentation on Cloudzy’s website. There is a $250-$1000 fine or NO WAY for unsuspension; this depends on the complaint type.

While these C2P entities are ostensibly legitimate businesses that may or may not know that their platforms are being abused for attack campaigns, they nonetheless provide a key pillar of the larger attack apparatus leveraged by some of the most advanced threat actors, the company said.

Cloudzy is just one player in the system, Smith said. If anything, the ransomware and cybercrime ecosystem is robust. Once an operation is burned, attackers will look to shift their C2 to other providers. As we saw with the collapse of Conti, all this does is leave a vacuum to be filled by another illicit organization.

(The article was updated after publication to include responses from Halcyon.)

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:41 am, Juni 1, 2025
Wetter-Symbol 17°C
L: 17° | H: 19°
wenige Wolken
Luftfeuchtigkeit: 57 %
Druck: 1014 mb
Wind: 14 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 14 mph 70 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 10 mph 82 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 16 mph 92 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 19°°C 0 mm 0% 13 mph 83 % 1010 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 15°°C 1 mm 100% 13 mph 97 % 1009 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 12 mph 52 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 14 mph 42 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 12 mph 51 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 70 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 82 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 48 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,668.35
0.44%
Ethereum(ETH)
€2,197.06
-1.13%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.89
-0.03%
Solana(SOL)
€134.12
-1.33%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.165747
0.01%
Shiba Inu(SHIB)
€0.000011
1.63%
Pepe(PEPE)
€0.000010
1.13%
Peanut das Eichhörnchen(PNUT)
€0.225383
1.50%
Nach oben scrollen