Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CloudSorcerer

Also known as: APT34, Earth Preta, Stately Taurus, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, TA446, GOSSAMER BEAR, TAG-53, IRON FRONTIER, UNC4057, COLD RELIC, Desert Falcon, Arid Viper, Bearded Barbie, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Ruinous Ursa, NIOBIUM, RENEGADE JACKAL, Scimitar

Description

CloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The malware leverages APIs and authentication tokens to access cloud resources for command and control, with GitHub serving as its initial C2 server. CloudSorcerer operates as separate modules depending on the process it's running in, executing from a single executable and utilizing complex inter-process communication through Windows pipes. The actor behind CloudSorcerer shows similarities to the CloudWizard APT in modus operandi, but the unique code and functionality suggest it is a new threat actor inspired by previous techniques.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Financial services
Non profit
Education
Think tank
Energy
Healthcare
Media
Critical infrastructure
Manufacturing
Aerospace
Maritime
Pharmaceutical
Legal services
Hospitality
Nuclear
Entertainment
Aviation
Chemical
Transportation
Utilities
Retail

Targeted Countries / Regions

RU
CN
UA
US
AE
IL
BY
PK
IN
VN
PL
KR
LB
TR
IR
TW
KZ
JP
IQ
DE
IT
SA
FR

AI Analysis

· 1 week ago

Executive Summary

CloudSorcerer is a sophisticated APT targeting Russian government entities, employing cloud infrastructure for stealthy operations including monitoring and data exfiltration. The group leverages APIs and authentication tokens to gain unauthorized access to cloud resources, utilizing GitHub as its initial command-and-control server. CloudSorcerer operates with modular malware, demonstrating similarities to the CloudWizard APT in modus operandi but exhibits unique code functionality.

Goals & Targeting

CloudSorcerer's strategic objectives appear to center on espionage and data theft, particularly targeting Russian government entities. The choice of cloud infrastructure for its operations indicates an interest in maintaining long-term persistence and low-key surveillance within targeted networks. The group's focus on API exploitation and token-based access suggests a desire to operate undetected while exfiltrating sensitive information.

Enhanced Description

CloudSorcerer has emerged as a notable advanced persistent threat (APT) group, specializing in targeting Russian government entities through sophisticated cyber operations. The group's primarymethodology involves leveraging cloud infrastructure for both command and control (C2) communication and data exfiltration activities. Unique to CloudSorcerer is its use of APIs and authentication tokens to access cloud resources, ensuring a level of stealthiness that allows it to evade traditional detection mechanisms. The malware employed by CloudSorcerer operates as separate modules depending on the process it's running in. This modular approach enables flexibility and adaptability, with all components executing from a single executable file. Communication between these modules is facilitated through complex inter-process interactions using Windows pipes, further reinforcing the operational efficiency and stealth of the group. While sharing similarities in tactics with other cloud-focused APTs like CloudWizard, CloudSorcerer demonstrates unique code functionality, suggesting it may be a newly emerging threat actor inspired by previous techniques.

Key Capabilities

  • Cloud Infrastructure Exploitation
  • API Exploitation for C2
  • Authentication Token Theft
  • Modular Malware Architecture
  • Inter-Process Communication via Windows Pipes

MITRE ATT&CK Tactics

Initial Access
Persistence
Defense Evasion
Credential Access
Exfiltration

ATT&CK Techniques

T1566.001
T1078
T1093
T1055.001
T1214

Software / Tooling

CloudSorcerer Malware
Custom C2 Framework Using GitHub

Campaigns & Victims

CloudSorcerer has demonstrated a patient and methodical approach, with operations appearing to be state-sponsored due to their focus on high-value targets in the Russian government sector. The group's campaigns exhibit a preference for long-term espionage over immediate破坏性 actions, aligning with APT behavior typically observed in nation-state actors. Notable operations include multiple campaigns leveraging cloud resources for C2 and data theft, though specific incidents remain limited in public reporting due to the group's relative newness.

IOC Patterns

  • Use of GitHub for initial C2 communication
  • API activity anomalies within cloud environments
  • Unusual authentication token usage patterns
  • Modular malware components communicating via Windows pipes

Recommended Actions

  • Implement strict API access controls and monitoring
  • Monitor for unusual GitHub-related network traffic
  • Enhance detection mechanisms for inter-process communication anomalies
  • Conduct regular audits of cloud infrastructure security posture

Suggested Tags

APT
espionage
cloud-attack
nation-state

Confidence Assessment

Medium confidence due to the uniqueness of the threat actor's code and its limited but targeted operations. The linkage to CloudWizard suggests a possible pattern, but more data is needed on weaponized campaigns. IOC patterns from similar groups can inform defensive measures.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 9 Filename 2 URL 4 IPv4 Address 5

References

  1. www.eset.com — Cited by web research for: APT34
  2. apt.etda.or.th — Cited by web research for: Turla
  3. securelist.com — Cited by web research for: Dark
  4. www.kaspersky.com — Cited by web research for: mspaint.exe

Intel Summary

2

Techniques

40

Tools

0

Campaigns

23

IOCs

0

Observed Data

2

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
Government Targeting
espionage
cloud-attack
nation-state

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.