Cloudwizard

Malware updated 2 months ago (2024-08-13T15:17:42.225Z)
Download STIX
Preview STIX
CloudWizard is a malicious software (malware) that has been used in advanced persistent threat (APT) campaigns. First reported by Kaspersky in 2023, it has been linked to cyber warfare activities in the Russo-Ukrainian conflict area. The malware operates by infiltrating systems and performing harmful actions such as taking screenshots, recording via the microphone, keylogging, and more. It also heavily leverages public cloud services for command and control (C2) operations. Despite similarities with the Prikormka malware used in Operation Groundbait, CloudWizard appears to be a distinct entity. In recent developments, Kaspersky discovered a new APT named "CloudSorcerer" targeting Russian government entities using similar tactics to CloudWizard, namely the use of cloud services for C2 operations. However, despite these operational similarities, there are significant differences between the two in terms of code and functionality. This suggests that while CloudSorcerer may have been inspired by CloudWizard's techniques, it is likely a new actor in the field of cyber espionage. The discovery of CloudSorcerer highlights the evolving landscape of cyber warfare actors. Despite some operational overlap, CloudSorcerer's unique code and functionality indicate that it is not a mere iteration of CloudWizard but a new player employing similar tactics. This underscores the importance of continued vigilance and adaptation in cybersecurity strategies, given the rapid evolution and diversification of threat actors.
Description last updated: 2024-08-13T15:16:56.549Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Commonmagic is a possible alias for Cloudwizard. CommonMagic is a malicious software framework that has been actively used since at least September 2021 to target government, agriculture, and transportation organizations located in the Donetsk, Lugansk, and Crimea regions. It was developed by an APT group linked to the Russo-Ukrainian conflict and
4
Prikormka is a possible alias for Cloudwizard. Prikormka is a type of malware that was used in Operation Groundbait, a cyber threat campaign that took place between 2008 and 2016. The malware is typically deployed through a dropper contained within malicious email attachments and has 13 different components designed to harvest various types of d
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Apt
Kaspersky
Malware
Encryption
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Cloudsorcerer Threat Actor is associated with Cloudwizard. CloudSorcerer is a newly identified threat actor discovered by Kaspersky, which targets Russian government entities using cloud services for command and control (C2) infrastructure. Similar to the previously reported CloudWizard Advanced Persistent Threat (APT), CloudSorcerer leverages public cloud Unspecified
3
Source Document References
Information about the Cloudwizard Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more