CN

Storm CloudStorm Cloud

Also known as: Storm Cloud

Origin
CN
Known aliases
1

Profile

Storm Cloud is a Chinese espionage threat actor known for targeting organizations across Asia, particularly Tibetan organizations and individuals. They use a variety of malware families, including GIMMICK and GOSLU, which are feature-rich and multi-platform. Storm Cloud leverages public cloud hosting services like Google Drive for command-and-control channels, making it difficult to detect their activities.

Aliases· 1

Storm Cloud

References

  1. https://www.volexity.com/blog/2020/03/31/storm-cloud-unleashed-tibetan-community-focus-of-highly-targeted-fake-flash-campaign/
  2. https://www.rewterz.com/rewterz-news/rewterz-threat-alert-gimmick-malware-active-iocs

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Storm-0558
Actor
Flax Typhoon
Actor
DriftingCloud
Actor
Dust Storm
Actor
Storm-0940
Actor
Storm-0062
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.