Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Russian Hackers Leverage Oracle Cloud Infrastructure to Scaleway Object Storage

## Cybersecurity: Russian Threat Actors Exploit Cloud Infrastructure

Cybersecurity: Russian Threat Actors Exploit Cloud Infrastructure

Recent investigations have revealed a cybersecurity attack wherein Russian threat actors are utilizing cloud service providers to propagate the Lumma Stealer malware. The attack leverages platforms like Oracle Cloud Infrastructure (OCI), Scaleway Object Storage, and Tigris for distributing malicious content targeting privileged users within various organizations.

The attackers employ social engineering tactics, including disguised free game downloads and fake reCAPTCHA verification pages. These elements are strategically hosted across different cloud providers, which makes detection and mitigation challenging.

Upon interaction with these elements, users inadvertently trigger a complex infection chain that facilitates the delivery of Lumma Stealer malware.

CATO Networks researchers identified the attack's deployment across multiple cloud providers as a strategy to enhance resilience. By distributing malicious components across Oracle Cloud Infrastructure, Scaleway, and Tigris, the attackers create redundancy, maintaining persistence even if one hosting location is blocked.

The attackers employ social engineering tactics, including disguised free game downloads and fake reCAPTCHA verification pages.
Jason Ford · Thehackingpost

The attack targets privileged users to access valuable organizational data or credentials, posing significant risks to enterprises.

The infection process begins when victims interact with disguised free game downloads or fake reCAPTCHA pages hosted on platforms like Tigris Object Storage. Users are directed to cloud-hosted content that appears legitimate but hides malicious code.

URLs such as "fly.storage.tigris.showing-next-go.html" on Tigris, and similar structures on Oracle Cloud and Scaleway, host these verification challenges leading to malware infection. Interaction results in downloading a ZIP archive with a signed executable that executes the Lumma Stealer from memory, harvesting credentials and other sensitive information.

Advertisement

The attackers use DLL search order hijacking, employing a malicious MpGear.dll file to ensure persistence on infected systems, allowing continuous data exfiltration.

Security professionals recommend deploying advanced threat detection systems for identifying suspicious cloud-hosted content. Implementing strict access controls for privileged users and comprehensive endpoint protection solutions is essential to mitigate risks posed by such campaigns.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories