{"id":4349,"date":"2024-07-08T16:25:26","date_gmt":"2024-07-08T21:25:26","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/cloudsorceror-public-cloud-cyberespionage-campaign"},"modified":"2024-07-08T16:25:26","modified_gmt":"2024-07-08T21:25:26","slug":"cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/08\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign\/","title":{"rendered":"&#8216;CloudSorcerer&#8217; Leverages Cloud Services in Cyber-Espionage Campaign"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8a4bc3220f1ed81e\/668c5ba5ff9e0ef1e68b9def\/wizard_Thomas_Mucha_alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A new cyber-espionage actor is targeting government organizations in the Russian Federation with a sophisticated piece of malware that can adapt its behavior based on its execution environment.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The advanced persistent threat (APT) group, which researchers at Kaspersky are tracking as &#8220;CloudSorcerer,&#8221; has an operational style that is akin to that used by &#8220;CloudWizard&#8221; another APT that the security vendor spotted last year also targeting Russian entities.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Hiding in the Cloud\">Hiding in the Cloud<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like CloudWizard, the new threat group too heavily leverages public cloud services for command and control (C2) and other purposes. It also appears to be going after the same targets. But CloudSorcerer&#8217;s eponymously named malware is entirely different from that of CloudWizard, making it more than likely that the former is a new cyber-espionage actor that&#8217;s merely using the same tactics as the latter, Kaspersky <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/securelist.com\/cloudsorcerer-new-apt-cloud-actor\/113056\/\" rel=\"noopener\">said in a report this week<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While there are similarities in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">modus operandi <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/securelist.com\/cloudwizard-apt\/109722\/\" rel=\"noopener\">previously reported CloudWizard<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> APT, the significant differences in code and functionality suggest that CloudSorcerer is likely a new actor, possibly inspired by previous techniques but developing its own unique tools,&#8221; Kaspersky said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CloudSorcerer&#8217;s primary malware tool can perform multiple functions that include covert monitoring and data collection on compromised systems, and data exfiltration using legitimate cloud services such as Microsoft Graph API, Dropbox and Yandex cloud. CloudSorcerer also uses cloud services to host its command-and-control servers, which the malware then accesses through application programming interfaces APIs).<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"CloudSorcerer: A Sneaky Malware\">CloudSorcerer: A Sneaky Malware<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The threat actors have been distributing CloudSorcerer as a single executable file that however can operate as two separate modules\u2014a data collection module and a communication module\u2014depending on the execution content. The goal in distributing the malware in this fashion is to make it both easier to deploy and to hide.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The malware is executed manually by the attacker on an already infected machine,&#8221; according to Kaspersky. &#8220;It is initially a single Portable Executable (PE) binary written in C.&#8221;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Its functionality varies depending on the process in which it is executed. Upon execution, the malware calls the GetModuleFileNameA function to check which process it is running on. If the process happens to be mspaint.exe the malware functions as a back door and collects a variety of malicious functions including code execution and data collection.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The data that CloudSorcerer collects includes computer name, username, Windows version information and system uptime. The malware then sends the data to the C2 server. Depending on the response from the C2 server, the backdoor then executes one of multiple commands including those that instruct it to collect information from hard drives on the system; collect data from files and folders; execute shell commands; and to create and write data to any file on the compromised system.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The malware&#8217;s backdoor functionality also includes the ability to create processes for running malicious binaries, creating processes as a dedicated user, getting and stopping tasks, creating and changing services, deleting values from Windows registries, and modifying registry keys. When CloudSorcerer first executes, it communicates with an initial C2 server on GitHub, which is basically a webpage that contains instructions on the next sequence of steps the malware needs to take, Kaspersky said.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Paying Attention to Outbound Traffic\">Paying Attention to Outbound Traffic<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The practice by attackers of leveraging public cloud services to host C2 infrastructure, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/new-campaign-uses-public-cloud-infrastructure-to-spread-rats\" rel=\"noopener\">distribute malware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and other components of an attack chain is not new. Services like <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/microsoft-graph-api-emerges-as-top-attacker-tool-to-plot-data-theft\" rel=\"noopener\">Microsoft Graph API<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/unsung-github-features-anchor-novel-hacker-c2-infrastructure\" rel=\"noopener\">GitHub<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in particular have become popular among threat actors looking to sneak malware and malicious activity past enterprise defense mechanisms. Even so, the growing sophistication of attacks leveraging such services present a challenge for organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The CloudSorcerer malware represents a sophisticated toolset targeting Russian government entities,&#8221; Kaspersky noted. &#8220;Its use of cloud services such as Microsoft Graph, Yandex Cloud, and Dropbox for C2 infrastructure, along with GitHub for initial C2 communications, demonstrates a well-planned approach to cyber espionage.&#8221; Adding to the challenge is CloudSorcerer&#8217;s ability to dynamically adapt its behavior based on process context, Kaspersky noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Erich Kron, security awareness advocate at KnowBe4, said the new campaign shows why organizations cannot stop with monitoring only what&#8217;s coming into the network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While the initial C2 communication starting with GitHub is not unusual, it is a lesson in the importance of limiting outbound traffic from networks,&#8221; as well, he said in an emailed comment. &#8220;If most of the people within an organization have no need to access a commonly used website for command-and-control traffic such as this, it makes sense to block this traffic.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/cloudsorceror-public-cloud-cyberespionage-campaign\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new cyber-espionage actor is targeting government organizations in the<\/p>\n","protected":false},"author":12,"featured_media":4350,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=2560%2C1387&ssl=1",2560,1387,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=300%2C163&ssl=1",300,163,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=640%2C347&ssl=1",640,347,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=640%2C347&ssl=1",640,347,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=1536%2C832&ssl=1",1536,832,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=2048%2C1110&ssl=1",2048,1110,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=1024%2C555&ssl=1",1024,555,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cloudsorcerer-leverages-cloud-services-in-cyber-espionage-campaign-scaled.jpg?fit=2560%2C1387&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4349"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4349\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4350"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}