Economic news

Cloud company assisted 17 different government hacking groups -US researchers

2023.08.01 08:03


© Reuters. The home page of the Cloudzy internet service provider is seen in this photo illustration taken in Washington, U.S., July 31, 2023. REUTERS/Raphael Satter/Illustration

By Raphael Satter and Christopher Bing

(Reuters) – An obscure cloud service company has been providing state-sponsored hackers with internet services to spy on and extort their victims, a cybersecurity firm said in a report to be published on Tuesday.

Researchers at Texas-based Halcyon said a company called Cloudzy had been leasing server space and reselling it to no fewer than 17 different state-sponsored hacking groups from China, Russia, Iran, North Korea, India, Pakistan and Vietnam.

Cloudzy CEO Hannan Nozari disputed Halcyon’s assessment, saying that his firm couldn’t be held responsible for its clients, of which he estimated only 2% were malicious.

In an exchange over LinkedIn, Nozari told Reuters: “If you are a knife factory, are you responsible if someone misuses the knife? Trust me I hate those criminals and we do everything we can to get rid of them.”

Digital defenders say the case is an example of how hackers and ransomware gangs use small firms operating at the fringes of cyberspace to enable big hacks.

Halcyon estimated that roughly half of Cloudzy’s business was malicious, including renting services to two ransomware groups.

“It’s a rogues’ gallery on that through one provider,” said Halcyon executive Ryan Golden ahead of the report’s publication.

Halcyon arrived at its conclusion by mapping out Cloudzy’s digital footprint, in part by renting servers directly from the firm and by tying it to known hacking operations.

The cybersecurity firm CrowdStrike (NASDAQ:), which wasn’t involved in the research, said that it hadn’t seen state-sponsored hackers using Cloudzy. But it had seen other cybercriminal activity connected to it.

Cloudzy’s geographic base of operations is unclear.

Halcyon researchers analyzed Cloudzy’s employees’ social media, including LinkedIn and Facebook (NASDAQ:) postings, and found the firm is “almost certainly” a front for another internet hosting company called abrNOC, which Nozari runs from Tehran.

Nozari, who says he lives outside Iran but would not be more specific, told Reuters the companies are separate, although he acknowledged that abrNOC employees helped with Cloudzy’s operations. He didn’t provide details.

Cloudzy is registered under its previous name, RouterHosting, in Cyprus and the U.S. state of Wyoming, according to corporate records reviewed by Reuters and confirmed by Nozari. He said the company needed U.S. domicile to be able to register internet protocol addresses in America.

It’s not clear whether Nozari’s registered agent – CloudPeak Law, a Wyoming law firm based in the small city of Sheridan – was aware of the allegations against its client.

A woman who answered at CloudPeak Law’s office confirmed that her firm was RouterHosting’s agent but said that, due to client confidentiality, “that is the extent of what anyone in our firm is going to be able to tell you.” The firm didn’t respond to a follow-up email.

Cloudzy’s business model is typical of several small virtual private server providers that rent internet hosting services in exchange for cryptocurrency, no questions-asked, said Adam Meyers, an executive with CrowdStrike.

“There’s a whole ecosystem of ne’er-do-well kind of folks who are in this business,” he said.

Source link

Related Articles

Back to top button
bitcoin
Bitcoin (BTC) $ 63,111.91 0.69%
ethereum
Ethereum (ETH) $ 2,552.93 0.27%
tether
Tether (USDT) $ 1.00 0.04%
bnb
BNB (BNB) $ 586.24 2.45%
solana
Solana (SOL) $ 147.45 2.36%
usd-coin
USDC (USDC) $ 1.00 0.03%
xrp
XRP (XRP) $ 0.585046 0.52%
staked-ether
Lido Staked Ether (STETH) $ 2,551.38 0.35%
dogecoin
Dogecoin (DOGE) $ 0.106465 0.47%
the-open-network
Toncoin (TON) $ 5.57 3.29%
tron
TRON (TRX) $ 0.151828 0.18%
cardano
Cardano (ADA) $ 0.355063 1.03%
avalanche-2
Avalanche (AVAX) $ 27.56 3.13%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,008.74 0.13%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 62,976.87 0.71%
shiba-inu
Shiba Inu (SHIB) $ 0.000014 0.63%
weth
WETH (WETH) $ 2,553.10 0.22%
chainlink
Chainlink (LINK) $ 11.38 2.79%
bitcoin-cash
Bitcoin Cash (BCH) $ 337.57 0.81%
polkadot
Polkadot (DOT) $ 4.34 0.81%
dai
Dai (DAI) $ 1.00 0.04%
leo-token
LEO Token (LEO) $ 5.54 3.73%
uniswap
Uniswap (UNI) $ 6.77 1.13%
litecoin
Litecoin (LTC) $ 65.70 0.89%
near
NEAR Protocol (NEAR) $ 4.37 2.54%
wrapped-eeth
Wrapped eETH (WEETH) $ 2,675.70 0.10%
kaspa
Kaspa (KAS) $ 0.169596 0.45%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.62 0.60%
sui
Sui (SUI) $ 1.49 1.63%
internet-computer
Internet Computer (ICP) $ 8.38 2.41%
aptos
Aptos (APT) $ 7.72 8.14%
pepe
Pepe (PEPE) $ 0.000008 1.98%
monero
Monero (XMR) $ 178.14 0.02%
bittensor
Bittensor (TAO) $ 420.84 0.05%
first-digital-usd
First Digital USD (FDUSD) $ 1.00 0.02%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.401335 1.44%
stellar
Stellar (XLM) $ 0.097207 0.45%
ethereum-classic
Ethereum Classic (ETC) $ 19.15 0.46%
blockstack
Stacks (STX) $ 1.76 1.32%
ethena-usde
Ethena USDe (USDE) $ 0.999095 0.00%
immutable-x
Immutable (IMX) $ 1.55 1.14%
okb
OKB (OKB) $ 39.74 0.41%
crypto-com-chain
Cronos (CRO) $ 0.086434 2.30%
aave
Aave (AAVE) $ 150.40 2.52%
filecoin
Filecoin (FIL) $ 3.78 0.74%
arbitrum
Arbitrum (ARB) $ 0.577562 0.31%
render-token
Render (RENDER) $ 5.24 3.08%
injective-protocol
Injective (INJ) $ 20.86 1.40%
hedera-hashgraph
Hedera (HBAR) $ 0.054212 1.82%
mantle
Mantle (MNT) $ 0.603542 1.45%