Ceeloader Malware
Summary
The researchers also note that the cybergang is continuing to reveal new custom-made malware threats, this time in the form of a new downloader named Ceeloader. Nobelium also employs other evasion methods, such as residential IP addresses as proxies, VPS and VPN before accessing the compromised environment and more. In the campaigns, the hackers used legitimate Microsoft Azure-hosted systems apparently, due to the fact that their IP addresses had close proximity to the compromised network. Evidence suggests that the group either has strong ties to Russia or is outright a hacking division of the countrys Foreign Intelligence Service. The latest activities of the group follow this pattern, with the hackers being observed to exfiltrate multiple documents from their victims that are believed to contain information of particular interest to Russia.