, , , , , ,

Researchers claim US-registered cloud host facilitated state-backed cyberattacks

A little-known cloud company provided web hosting and internet services to more than two dozen different state-sponsored hacking groups and commercial spyware operators, according to researchers at cybersecurity company Halcyon.

In a report released on Tuesday, Halcyon said it had identified that the U.S.-registered company Cloudzy was “knowingly or unwittingly” acting as a command-and-control provider (C2P) to well-known state-sponsored hacking groups. C2Ps are internet providers that allow hackers to host virtual private servers and other anonymized services used by ransomware affiliates to carry out cyberattacks and extortion.

Halcyon said that the two-dozen groups that rely on Cloudzy include the China-backed espionage group APT10; North Korea-backed hackers Kimsuky; and Kremlin-backed groups Turla, Nobelium, and FIN12.

FIN12 was the subject of a joint FBI-CISA advisory in October 2020 after carrying out a spate of ransomware attacks targeting the U.S. healthcare industry. In its report, Halcyon said that Cloudzy — then doing business as Router Hosting — hosted at least 40 command and control servers used by FIN12 during its cyberattacks.

The list of groups facilitated by Cloudzy also includes hacking groups from Iran, Pakistan and Vietnam, along with Tel Aviv-based malware maker Candiru, which sells its phone-snooping spyware to government customers. Candiru was sanctioned by the U.S. government in 2021 for engaging in activities contrary to U.S. national security.

Halcyon says that about half of the total servers hosted by Cloudzy appear to be directly supporting malicious activity.

The cybersecurity firm concluded that although the cloud host is registered in the U.S., Halcyon says it has “high confidence” that the cloud host is as a cutout for AbrNOC, a cloud host that operates out of the Iranian capital of Tehran, which could put American customers in conflict with U.S. government sanctions.

Cloudzy, which claims to operate out of New York City, is registered in Wyoming, while a support phone number listed by the company is linked to a different address in Las Vegas. AbrNOC shares the same logo as Cloudzy, albeit in a different color, and also shares the same fictitiously named employees, according to Halcyon researchers. A man named Hannan Nozari is listed as abrNOC’s CEO and identifies himself as the founder of both web hosts companies in his Twitter bio, as well as a “Noob on the Internet.”

Nozari did not respond to messages sent by TechCrunch via LinkedIn and email, and TechCrunch was unable to reach anyone at Cloudzy via the number listed on the company’s website.

Reuters, which first reported the cybersecurity firm’s findings, said it had spoken to Nozari, who said that he was not responsible for his customers’ actions and that his company does “everything we can to get rid of them,” adding that he estimated only 2% of the company’s clients were malicious.

As noted by Halcyon, Cloudzy markets itself in a manner that “directly appeals not just to privacy enthusiasts, but also to threat actors.” The hosting provider only requires a working email address and an anonymous payment in cryptocurrency. Monero, a privacy coin favored by hackers, is supported.

The researchers also found that while Cloudzy’s website states that illegal activities are not allowed on its service and will result in immediate termination, a different section on its website says that if bad actors paid a nominal $250-100 fine, they might be able to continue to use their service.

https://techcrunch.com/2023/08/01/cloudzy-hosting-provider-facilitated-state-sponsored-cyberattacks/


July 2024
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 987: Often Plagiarized, Never Equalled – Sapce Junk, Threads Hits 175M Users, AIndependence This Week in Tech (Audio)

Why Surgeon General's Social Media Warning Label is a Bad Idea Russia says Apple blocks 25 VPN apps in Russia, IFX reports Microsoft MSFT Tells Texas Agencies They Were Exposed in Russian Hack Microsoft says it's okay to steal content published on the web Declare your AIndependence: block AI bots, scrapers and crawlers with a single click Perplexity's grand theft AI The Julian Assange Saga Is Finally Over Zotac's Big Mistake | Consumer Warranty & Business Data Exposure NASA and SpaceX misjudged the risks from reentering space junk The White House will host a conference for social media creators Meta's Threads hits 175 million users one year after launch Google emissions jump nearly 50% over five years as AI use surges Judge blocks Mississippi law that required age verification on social media Host: Leo Laporte Guests: Paris Martineau, Allyn Malventano, and Larry Magid Download or subscribe to this show at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: panoptica.app expressvpn.com/twit NetSuite.com/TWIT 1password.com/twit
  1. TWiT 987: Often Plagiarized, Never Equalled – Sapce Junk, Threads Hits 175M Users, AIndependence
  2. TWiT 986: Our Dope GPS! – Supreme Court Decisions, Snapdragon X Elite Tests
  3. TWiT 985: TikTok With Wings – AT&T Landlines, US Bans Kaspersky and DJI
  4. TWiT 984: Fifty-three Clicks – Bot Farms in Ukraine, LA Public Health Dept. Phished
  5. TWiT 983: Digital Snackwells – NVIDIA's Thor, Adobe's TOS, Insta's Unskippable Ads