Cloud company assisted 17 different government hacking groups: US researchers

Published August 1, 2023
The home page of the Cloudzy internet service provider is seen in this photo illustration taken in Washington, US on July 31, 2023. — Reuters
The home page of the Cloudzy internet service provider is seen in this photo illustration taken in Washington, US on July 31, 2023. — Reuters

An obscure cloud service company has been providing state-sponsored hackers with internet services to spy on and extort their victims, a cybersecurity firm said in a report published on Tuesday.

Researchers at Texas-based Halcyon said a company called Cloudzy had been leasing server space and reselling it to no fewer than 17 different state-sponsored hacking groups, purportedly, from Pakistan, China, Russia, Iran, North Korea, India and Vietnam.

Cloudzy Chief Executive Officer Hannan Nozari disputed Halcyon’s assessment, saying that his firm couldn’t be held responsible for its clients, of which he estimated only two per cent were malicious.

In an exchange over LinkedIn, Nozari told Reuters: “If you are a knife factory, are you responsible if someone misuses the knife? Trust me I hate those criminals and we do everything we can to get rid of them.”

Digital defenders say the case is an example of how hackers and ransomware gangs use small firms operating at the fringes of cyberspace to enable big hacks.

The cybersecurity firm CrowdStrike, which wasn’t involved in the research, said that it hadn’t seen state-sponsored hackers using Cloudzy. But it had seen other cybercriminal activity connected to it.

Cloudzy’s geographic base of operations is unclear.

Halcyon researchers analysed Cloudzy’s employees’ social media, including LinkedIn and Facebook postings, and found the firm is “almost certainly” a front for another internet hosting company called abrNOC, which Nozari runs from Tehran.

Nozari, who says he lives outside Iran but would not be more specific, told Reuters the companies are separate, although he acknowledged that abrNOC employees helped with Cloudzy’s operations. He didn’t provide details.

Cloudzy is registered under its previous name, RouterHosting, in Cyprus and the US state of Wyoming, according to corporate records reviewed by Reuters and confirmed by Nozari. He said the company needed a US domicile to be able to register internet protocol addresses in America.

It’s not clear whether Nozari’s registered agent — CloudPeak Law, a Wyoming law firm based in the small city of Sheridan — was aware of the allegations against its client.

A woman who answered at CloudPeak Law’s office confirmed that her firm was RouterHosting’s agent but said that, due to client confidentiality, “that is the extent of what anyone in our firm is going to be able to tell you.” The firm didn’t respond to a follow-up email.

Cloudzy’s business model is typical of several small virtual private server providers that rent internet hosting services in exchange for cryptocurrency, no questions-asked, said Adam Meyers, an executive with CrowdStrike.

“There’s a whole ecosystem of ne’er-do-well kind of folks who are in this business,” he said.

Opinion

Editorial

Poll petitions’ delay
Updated 06 Jan, 2025

Poll petitions’ delay

THOUGH electoral transparency and justice are essential for the health of any democracy, the relevant quarters in...
Migration racket
06 Jan, 2025

Migration racket

A KEY part of dismantling human smuggling and illegal migration rackets in the country — along with busting the...
Power planning
06 Jan, 2025

Power planning

THE National Electric Power Regulatory Authority, the power sector regulator, has rightly blamed poor planning for...
Confused state
Updated 05 Jan, 2025

Confused state

WHEN it comes to combatting violent terrorism, the state’s efforts seem to be suffering from a lack of focus. The...
Born into hunger
05 Jan, 2025

Born into hunger

OVER 18.2 million children — 35 every minute — were born into hunger in 2024, with Pakistan accounting for 1.4m...
Tourism triumph
05 Jan, 2025

Tourism triumph

THE inclusion of Gilgit-Baltistan in CNN’s list of top 25 destinations to visit in 2025 is a proud moment for...