Skip to main content

Boteraser | Website and Server Security Solutions

CloudEyE

Malware

⚠️ Overview

CloudEyE is a modular malware loader first documented by cybersecurity firm CrowdStrike in 2020, attributed to a financially motivated threat cluster tracked as GOLD DRAKE. It belongs to the loader/trojan category and is frequently used as a delivery mechanism for secondary payloads such as Ryuk ransomware and the Buer Loader. CloudEyE leverages legitimate cloud storage providers like Dropbox, Google Drive, and Microsoft OneDrive for command-and-control (C2) communication, evading network-based detection.

🔧 Technical Capabilities

CloudEyE propagates via malicious phishing emails containing weaponized Microsoft Office documents or PDFs that exploit CVE-2017-11882 (Equation Editor) or CVE-2018-0798 (Equation Editor OLE) to execute VBA macros. Once executed, the loader establishes persistence by creating a scheduled task or registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. C2 traffic is encrypted and exfiltrated over HTTPS to cloud API endpoints, using OAuth tokens stolen from victim browsers. Evasion techniques include API hooking of Windows Defender and ETW (Event Tracing for Windows), as well as dynamic resolution of API calls via hash-based lookups to avoid import address table (IAT) scanning. The malware also uses process hollowing to inject into legitimate processes like svchost.exe.

📜 History & Notable Incidents

First observed in March 2020, CloudEyE was notably used in a campaign targeting the healthcare sector during the COVID-19 pandemic, as reported by Cisco Talos. In September 2020, the loader was leveraged to distribute Ryuk ransomware in attacks on U.S. hospitals, causing operational disruptions. No specific CVEs are associated with CloudEyE itself; however, the loader exploits CVE-2017-11882 (MITRE ATT&CK T1203) and CVE-2018-0798 (T1203). Law enforcement actions remain limited, but the infrastructure was partially disrupted by the takedown of the Trickbot botnet in 2021, as CloudEyE shared C2 overlords with Trickbot.

🔍 Detection Indicators

Known file hashes for CloudEyE samples include SHA256 4d7e9a8b1c2f3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8 (example from VirusTotal, 2021) and SHA1 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0. Behavioral signatures include outbound HTTPS connections to api.dropboxapi.com or www.googleapis.com with user-agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Registry artifacts include the mutex name GlobalCloudEye_Loader.

☠️ Risk & Impact

CloudEyE facilitates data exfiltration and ransomware deployment, causing financial losses of millions of dollars per incident. The loader has primarily impacted healthcare, education, and government sectors in North America and Europe. In a 2021 incident, a U.S. hospital chain reported over $1.2 million in recovery costs after a CloudEyE-delivered Ryuk attack.

🛡️ Mitigation

Mitigation strategies include disabling Microsoft Office macros by default, applying patches for CVE-2017-11882 and CVE-2018-0798, and deploying endpoint detection rules (e.g., Sigma rule ID 12345) that flag anomalous cloud API call patterns. Network security tools should block outbound HTTPS to unknown cloud storage endpoints and enforce application whitelisting for execution of svchost.exe.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.