PULSE NAME
Evasive Panda scouting cloud services
WHITE Evasive Panda AlienVault 2024-10-28 Modified: 2024-11-27
76
IOCs
HIGH VOLUME
CloudScout is a post-compromise toolset used by Evasive Panda to target a Taiwanese government entity and religious organization between 2022 and 2023. The toolset can retrieve data from various cloud services using stolen web session cookies. It works with MgBot, Evasive Panda's malware framework, through a plugin. Three CloudScout modules were analyzed, targeting Google Drive, Gmail, and Outlook. The modules are deployed by MgBot plugins and use stolen cookies to access and exfiltrate cloud data. CloudScout's design includes a common architecture across modules and a core CommonUtilities package. The toolset demonstrates Evasive Panda's technical capabilities and focus on cloud-stored data in espionage operations.
Indicators of Compromise (13 / 76 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 07df8d223f8a370cd703d177d7e93a36 2024-10-28
FileHash-MD5 13546e9d36effa74f971d90687b60ea6 2024-10-28
FileHash-MD5 4c504e0ef91fc66a6d6c4e3d6b10fa18 2024-10-28
FileHash-MD5 889a7ae42fb44390ab99af071dd3d6b0 2024-10-28
FileHash-MD5 9f27e0798271b590a01463d4543df2ea 2024-10-28
FileHash-MD5 ae5d92ef69074050a822f6669fe267b6 2024-10-28
FileHash-MD5 b2a36442e68848944365d3d1b8b7554a 2024-10-28
FileHash-MD5 be17d056039267973e36043c678a5d56 2024-10-28
FileHash-MD5 c02b6a7cc4f4da2d6956049b90ff53ba 2024-10-28
FileHash-MD5 d7a70062736c8d34823cfb835cf5c34c 2024-10-28
FileHash-MD5 d93af224d9e9a5172bb9ba5104e24a45 2024-10-28
FileHash-MD5 eef23748ed175760f9c70871252a11f3 2024-10-28
FileHash-MD5 f553ea019b79742eabcbacd387231623 2024-10-28