Join Halcyon @ RSA 2024

Learn more
Research

Report: Ransomware Command-and-Control Providers Unmasked by Halcyon Researchers

Written by
Halcyon Team
Published on
August 1, 2023

The Halcyon Research and Engineering Team has published new research that details novel techniques used to unmask yet another Ransomware Economy player that is facilitating ransomware attacks and state-sponsored APT operations: Command-and-Control Providers (C2P) who sell services to threat actors while assuming a legal business profile.

While these C2P entities are ostensibly legitimate businesses that may or may not know that their platforms are being abused for attack campaigns, they nonetheless provide a key pillar of the larger attack apparatus leveraged by some of the most advanced threat actors.

In this report, titled Cloudzy with a Chance of Ransomware: Unmasking Command-and-Control Providers (C2Ps), Halcyon demonstrates a unique method for identifying C2P entities that can be used to forecast the precursors to major ransomware campaigns and other advanced attacks significantly “left of boom.” Halcyon also identifies two new, previously undisclosed ransomware affiliates Halcyon tracks as Ghost Clown and Space Kook that currently deploy BlackBasta and Royal, respectively.

The report also describes how we used the same method to link the two ransomware affiliates to the same Internet Service Provider, Cloudzy, which accepts cryptocurrencies in exchange for anonymous use of its Remote Desktop Protocol (RDP) Virtual Private Server (VPS) services.

Inset Image Banner to download Halcyon's Cloudzy Report PDF.

Download the Full Report Here (PDF)

Key Findings:

  • Halcyon asserts that, based on this research, there is yet another key player supporting the burgeoning ransomware economy: Command-and-Control Providers(C2P) who – knowingly or not - provide services to attackers while assuming a legitimate business profile.  
  • Threat actors that are assessed to be leveraging Cloudzy include APT groups tied to the Chinese, Iranian, North Korean, Russian, Indian, Pakistani, and Vietnamese governments; a sanctioned Israeli spyware vendor whose tools are known to target civilians; several criminal syndicates and ransomware affiliates whose campaigns have spurred international headlines.
  • Halcyon uses an unlikely pivot point - namely RDP hostnames within the metadata of an affiliate’s attack infrastructure – that can enable security teams to detect imminent ransomware attacks before they are launched as the attack infrastructure is being stood up.  
  • Halcyon identifies that Cloudzy - which accepts cryptocurrencies in exchange for anonymous use of its Remote Desktop Protocol (RDP) Virtual Private Server (VPS)services – appears to be the common service provider supporting ransomware attacks and other cybercriminal endeavors.
  • Halcyon also identifies a long list of government-sponsored APT-related attacks spanning several years that appear to be using Cloudzy services, where it is assessed that (potentially) between 40% - 60% of of the overall activity could be considered malicious in nature.
  • Halcyon presents evidence that, although Cloudzy is incorporated in the United States, it almost certainly operates out of Tehran, Iran – in possible violation of U.S. sanctions – under the direction of someone going by the name Hassan Nozari.  
  • Halcyon identified two previously unknown ransomware affiliates dubbed Ghost Clown and Space Kook currently deploying BlackBasta and Royal ransomware strains, respectively.

This report documents what is assessed to be a pattern of consistent use or abuse of servers provided by Internet Service Provider Cloudzy by more than two dozen different threat actors, including:

  • Groups tied to the Chinese, Iranian, North Korean, Russian, Indian, Pakistani, and Vietnamese governments
  • A sanctioned Israeli spyware vendor whose tools are known to target civil society
  • Several additional criminal syndicates and ransomware affiliates whose campaigns previously made international headlines.

Halcyon concludes this report by taking a closer look at ISP Cloudzy, and presents evidence that even though Cloudzy purports to be an American-based company, it is assessed to actually be operating out of Tehran, Iran, possibly in violation of U.S. sanctions.

Halcyon recommends that the technical readers of this report use the indicators of compromise appended below to search their networks for any of the malicious activity we tied to C2P Cloudzy, and that they immediately take note when any of the 11 RDP hostnames we identified surface in their environments.  

We recommend that defenders look out for these hostnames both retroactively, to identify possible attacks already in progress, but also proactively, to prevent any malicious activity to begin with.

Indicators of Compromise:

SHA256
4d56e0a878b8a0f04462e7aa2a47d69a6f3a31703563025fb40fb82bab2a2f05

SHA256
b27ca5155e42e372d37cf2bcbb1f159627881ecbae2e51d41f414429599d37a7

IP Addresses
23.19.58[.]181
139.177.146[.]152
172.93.201[.]120

Domain
mojimetigi[.]biz

Netblocks

104.237.193.40/29

104.237.193.56/29

104.237.194.152/29

104.237.219.32/29

104.237.219.40/29

167.88.4.0/29

167.88.4.112/29

167.88.4.16/29

167.88.4.24/29

167.88.4.8/29

172.86.120.0/22

172.93.179.8/29

172.93.179.24/29

172.93.179.32/29

172.93.179.40/29

172.93.179.72/29

172.93.179.96/29

172.93.179.104/29

172.93.179.112/29

172.93.179.120/29

172.93.179.128/29

172.93.179.144/29

172.93.179.152/29

172.93.179.160/29

172.93.179.176/29

172.93.179.184/29

172.93.179.192/29

172.93.179.200/29

172.93.179.208/29

172.93.179.224/29

172.93.179.232/29

172.93.179.240/29

172.93.179.248/29

172.93.181.0/24

172.93.193.0/24

172.93.201.0/24

172.93.204.120/29

172.93.205.128/29

172.93.205.136/29

172.93.205.144/29

64.44.101.0/24

64.44.102.0/24

64.44.134.0/29

64.44.134.16/29

64.44.134.24/29

64.44.134.32/29

64.44.134.40/29

64.44.134.48/29

64.44.134.56/29

64.44.135.0/24

64.44.140.232/29

64.44.141.0/24

64.44.51.168/29

64.44.97.0/24

64.44.98.0/24

Halcyon.ai is the industry’s first dedicated, adaptive security platform that combines multiple advanced proprietary prevention engines along with AI models focused specifically on stopping ransomware – talk to a Halcyon expert today to find out more. Halcyon also publishes a quarterly RaaS and extortion group reference guide, Power Rankings: Ransomware Malicious Quartile Q2 2023 (PDF).

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

The Halcyon Platform

Halcyon is the industry’s first dedicated, adaptive security platform focused specifically on stopping ransomware attacks. Halcyon is built by attackers to stop attackers. The solution is a lightweight agent that combines multiple proprietary advanced prevention engines along with AI models trained solely on ransomware.

Interested in getting a demo? Fill out the form and let’s talk!

Get a Demo

Meet with a Halcyon Anti-Ransomware Expert