Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

CloudSorcerer

CloudSorcerer is a backdoor used in cyber-espionage activity and notably observed in attacks against Russian entities, including Russian government entities, in 2024. Reporting also links its use to the China-nexus threat activity cluster UAT-8302, which Cisco Talos said targeted government agencies in South America since late 2024 and southeastern Europe in 2025, and to APT31 activity targeting Russia’s IT sector. CloudSorcerer is characterized by its use of legitimate cloud services for command-and-control, including OneDrive, Dropbox, and Yandex Cloud; additional reporting states CloudSorcerer v3 can obtain C2 information from GitHub repositories and GameSpot profiles. In Talos reporting, CloudSorcerer version 3 collects system details when injected into dnapimg.exe and then pivots into explorer.exe for named-pipe command handling, while in spoolsv.exe it can contact a GitHub repository for command retrieval. The malware is associated with long-term access and data theft operations against government and related entities. Infection and deployment context mentioned in the source material includes DLL side-loading and broader post-compromise deployment alongside other implants such as NetDraft and VSHELL. High-confidence infrastructure details specific to the broader UAT-8302 activity include command-and-control domains such as update-kaspersky[.]workers[.]dev and related campaign infrastructure including msiidentity[.]com, drivelivelime[.]com, trafficmanagerupdate[.]com, and IP address 85[.]209[.]156[.]3, though the content does not attribute all of these exclusively to CloudSorcerer.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAT-8302

The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.

via cyber security newscybersecuritynews.com
ZIRCONIUM

CloudSorcerer, a backdoor that used cloud services as C2

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1559.001Component Object ModelEvidence1
TacticExecution

If injected into “dnapimg.exe,” it collects system details and pivots into explorer.exe to receive commands through a named pipe channel.

T1055Process InjectionEvidence1

CloudSorcerer version 3 behaves differently depending on which process it runs inside. If injected into “dnapimg.exe,” it collects system details and pivots into explorer.exe to receive commands through a named pipe channel.

Stealth

1 technique
T1055Process InjectionEvidence1

CloudSorcerer version 3 behaves differently depending on which process it runs inside. If injected into “dnapimg.exe,” it collects system details and pivots into explorer.exe to receive commands through a named pipe channel.

Discovery

1 technique
T1082System Information DiscoveryEvidence1
TacticDiscovery

If injected into “dnapimg.exe,” it collects system details...

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.