CloudSorcerer is a threat actor associated with cyberespionage activity against Russian government entities. The group has been observed using custom malware that leverages legitimate public cloud services for command-and-control communications and data storage, a tradecraft choice that supports stealth and defense evasion by blending malicious traffic with trusted platforms. Reported activity indicates a focus on government targets and the use of bespoke tooling rather than commodity malware. Based on the available information, CloudSorcerer is best characterized as an espionage-oriented actor with capabilities in initial access, persistence, exfiltration, and defense evasion. No high-confidence attribution to a specific state or country of origin is established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CloudSorcerer is mentioned in the CTI Roundup: Threat Actor Updates.
CloudSorcerer is an emerging APT group using custom malware and public cloud services for C2 and data storage, targeting Russian government entities for cyberespionage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.