CloudSorcerer
CloudSorcerer is a backdoor used in cyber-espionage activity and notably observed in attacks against Russian entities, including Russian government entities, in 2024. Reporting also links its use to the China-nexus threat activity cluster UAT-8302, which Cisco Talos said targeted government agencies in South America since late 2024 and southeastern Europe in 2025, and to APT31 activity targeting Russia’s IT sector. CloudSorcerer is characterized by its use of legitimate cloud services for command-and-control, including OneDrive, Dropbox, and Yandex Cloud; additional reporting states CloudSorcerer v3 can obtain C2 information from GitHub repositories and GameSpot profiles. In Talos reporting, CloudSorcerer version 3 collects system details when injected into dnapimg.exe and then pivots into explorer.exe for named-pipe command handling, while in spoolsv.exe it can contact a GitHub repository for command retrieval. The malware is associated with long-term access and data theft operations against government and related entities. Infection and deployment context mentioned in the source material includes DLL side-loading and broader post-compromise deployment alongside other implants such as NetDraft and VSHELL. High-confidence infrastructure details specific to the broader UAT-8302 activity include command-and-control domains such as update-kaspersky[.]workers[.]dev and related campaign infrastructure including msiidentity[.]com, drivelivelime[.]com, trafficmanagerupdate[.]com, and IP address 85[.]209[.]156[.]3, though the content does not attribute all of these exclusively to CloudSorcerer.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group deploys NetDraft, a .NET-based backdoor linked to the FinDraft and SquidDoor family, alongside an updated version of the CloudSorcerer backdoor and the VSHELL implant.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 techniqueIf injected into “dnapimg.exe,” it collects system details and pivots into explorer.exe to receive commands through a named pipe channel.
Privilege Escalation
1 techniqueStealth
1 techniqueDiscovery
1 techniqueIf injected into “dnapimg.exe,” it collects system details...
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor whose behavior changes based on the host process. When injected into dnapimg.exe it collects system details and pivots into explorer.exe to receive commands through a named pipe; when running in spoolsv.exe it contacts a GitHub repository to retrieve command-and-control information.
Backdoor observed in attacks against Russian entities and later deployed by UAT-8302.
A backdoor delivered through DLL sideloading and shellcode decryption/injection. It gathers system information, injects into benign processes, executes commands, performs file operations, and retrieves C2 details from legitimate services such as GitHub, GameSpot, OneDrive, or Dropbox.
A backdoor malware used by APT31 that can utilize multiple commercial cloud services (OneDrive, Dropbox, Yandex Cloud) for C2, making detection and blocking more difficult.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.