DriftingCloud
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Aliases: APT DRIFTINGCLOUD
DriftingCloud is a cyber espionage threat actor assessed with high confidence to be of Chinese origin. The group first emerged with documented activity in April 2020 and primarily focuses on intelligence gathering. What distinguishes DriftingCloud is its consistent use of zero-day vulnerabilities in public-facing network devices, such as firewalls, to establish initial access and perform man-in-the-middle attacks for credential and session cookie theft. The group is known for its stealthy approach and its ability to develop or acquire zero-day exploits, tipping the scales in their favor when it comes to gaining entry to target networks. This group does not operate under multiple publicly known names and is not commonly confused with other unrelated threat actors.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
| Tipo | Estado | Host / enlace | Title / ultimo titulo |
| Repositorio | unknown | github.com | APT DRIFTINGCLOUD indicators and references |
| DLS / leak site | unknown | www.volexity.com | APT DRIFTINGCLOUD indicators and references |
| Repositorio | unknown | github.com | APT DRIFTINGCLOUD indicators and references |
| DLS / leak site | unknown | raw.githubusercontent.com | APT DRIFTINGCLOUD indicators and references |
| Repositorio | unknown | 158.247.200.24APTTrailURLhttp | APT DRIFTINGCLOUD indicators and references |
Sectores objetivo (SOCRadar)
Public AdministrationTelecommunicationsBankingComputer Systems Design and Related Services