CloudEyE MaaS Downloader and Cryptor Infects Over 100,000 Users Globally
ESET Research has reported a substantial increase in CloudEye malware detections, showing a 30-fold rise in the second half of 2025. The firm identified over 100,000 infection attempts during this period, indicating a global threat to organizations.
ESET Research has reported a substantial increase in CloudEye malware detections, showing a 30-fold rise in the second half of 2025. The firm identified over 100,000 infection attempts during this period, indicating a global threat to organizations.
CloudEye functions as a Malware-as-a-Service (MaaS) downloader and cryptor, designed to deploy secondary payloads such as Rescoms, Formbook, and Agent Tesla, which are known for information stealing and remote access.
This increase reflects a shift in malware distribution tactics, utilizing platforms like ransomware-as-a-service and malware-as-a-service. CloudEye acts as a covert delivery mechanism, facilitating the distribution of various malware families while maintaining operational flexibility and anonymity. This modular approach allows attackers to customize payloads based on the target environment, enhancing campaign effectiveness.
CloudEye employs a sophisticated multi-stage architecture to maximize evasion capabilities. The initial stage involves downloader components spread through PowerShell scripts, JavaScript files, and NSIS executables, typically delivered via spearphishing emails, drive-by downloads, and compromised websites. Once executed, the downloader retrieves the cryptor component containing the final payload.
ESET Research has reported a substantial increase in CloudEye malware detections, showing a 30-fold rise in the second half of 2025.
A distinguishing feature of CloudEye is its extensive obfuscation across all infection stages, making it resistant to endpoint detection and response (EDR) solutions, static analysis, and threat intelligence databases. This layered obfuscation complicates forensic analysis, allowing the malware to persist longer within target environments.
Geographic analysis shows concentrated targeting in Central and Eastern Europe, accounting for 32 percent of infection attempts during the second half of 2025. ESET observed coordinated email campaigns during September and October 2025, suggesting organized distribution by sophisticated threat actors. The geographic focus indicates targeted operations, possibly aimed at specific industry sectors or vulnerabilities within these regions.
The rise of CloudEye highlights the evolving threat landscape, where modular malware architectures and MaaS platforms democratize malware distribution. Organizations must acknowledge the limitations of traditional signature-based detection mechanisms against heavily obfuscated payloads. The reliance on legitimate system tools like PowerShell and JavaScript in the infection chain underscores the challenge of distinguishing malicious activity from normal operations.
To counter this, organizations should implement behavioral-based detection systems capable of identifying suspicious PowerShell and JavaScript execution patterns. Email security filtering should focus on blocking NSIS executables and suspicious script attachments. Additionally, endpoint detection and response solutions with advanced heuristics and machine learning can provide better visibility into obfuscated threat activity. User security awareness training remains essential, as spearphishing is the primary infection vector for CloudEye distribution.
The milestone of over 100,000 infections demonstrates the operational maturity and reach of CloudEye’s infrastructure. Continuous monitoring of this threat is critical due to its modular design, allowing for rapid evolution and adaptation.
Based on reporting by GBHackers.
