Russian Hackers Leverage Oracle Cloud Infrastructure to Scaleway Object Storage
## Cybersecurity: Russian Threat Actors Exploit Cloud Infrastructure
Cybersecurity: Russian Threat Actors Exploit Cloud Infrastructure
Recent investigations have revealed a cybersecurity attack wherein Russian threat actors are utilizing cloud service providers to propagate the Lumma Stealer malware. The attack leverages platforms like Oracle Cloud Infrastructure (OCI), Scaleway Object Storage, and Tigris for distributing malicious content targeting privileged users within various organizations.
The attackers employ social engineering tactics, including disguised free game downloads and fake reCAPTCHA verification pages. These elements are strategically hosted across different cloud providers, which makes detection and mitigation challenging.
Upon interaction with these elements, users inadvertently trigger a complex infection chain that facilitates the delivery of Lumma Stealer malware.
CATO Networks researchers identified the attack's deployment across multiple cloud providers as a strategy to enhance resilience. By distributing malicious components across Oracle Cloud Infrastructure, Scaleway, and Tigris, the attackers create redundancy, maintaining persistence even if one hosting location is blocked.
The attackers employ social engineering tactics, including disguised free game downloads and fake reCAPTCHA verification pages.
The attack targets privileged users to access valuable organizational data or credentials, posing significant risks to enterprises.
The infection process begins when victims interact with disguised free game downloads or fake reCAPTCHA pages hosted on platforms like Tigris Object Storage. Users are directed to cloud-hosted content that appears legitimate but hides malicious code.
URLs such as "fly.storage.tigris.showing-next-go.html" on Tigris, and similar structures on Oracle Cloud and Scaleway, host these verification challenges leading to malware infection. Interaction results in downloading a ZIP archive with a signed executable that executes the Lumma Stealer from memory, harvesting credentials and other sensitive information.
The attackers use DLL search order hijacking, employing a malicious MpGear.dll file to ensure persistence on infected systems, allowing continuous data exfiltration.
Security professionals recommend deploying advanced threat detection systems for identifying suspicious cloud-hosted content. Implementing strict access controls for privileged users and comprehensive endpoint protection solutions is essential to mitigate risks posed by such campaigns.
Based on reporting by Cyber Security News.
