#CloudReverser
Incident/Operation
2024-05-21 • Analysis and Detection of CLOUD#REVERSER: An Attack Involving Threat Actors Compromising Systems Using A Sophisticated Cloud-Based Malware
CLOUD#REVERSER is a cloud-enabled malware campaign that began with phishing emails carrying ZIP archives whose executable payloads masqueraded as Microsoft Excel documents. Execution opened a lure spreadsheet while dropping VBScript and PowerShell components, establishing minute-by-minute scheduled-task persistence under names resembling legitimate Google update tasks, and cleaning up intermediate scripts. The infection chain abused Google Drive and Dropbox to stage payloads, retrieve commands, update operational scripts, and exfiltrate data, allowing malicious traffic and storage activity to blend with widely trusted cloud services.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days