The Nobelium hacking group continues to breach government and corporate networks globally, targeting cloud and managed service providers using the new custom malware “Ceeloader”.

See also: Magnat Campaign: Malware Spreads Through Fake Software Downloads
Nobelium is the name Microsoft has given to the threat actor behind last year's SolarWinds that led to the breach of several U.S. federal agencies. This group is believed to be the hacking arm of the Russian Foreign Intelligence Service (SVR), commonly known as APT29, The Dukes, or Cozy Bear.
While Nobelium is an advanced hacking group that uses custom malware and tools, it still leaves traces of activity that researchers can use to analyze its attacks.
In a new report from Mandiant, researchers used this activity to uncover tactics, techniques, and procedures (TTPs) used by the hacking group, as well as a new custom downloader called “Ceeloader.”.
Furthermore, the researchers divide Nobelium into two separate activity clusters attributed to UNC3004 and UNC2652, which could mean that Nobelium is two collaborating hacking groups.
See also: A simple technique enhances phishing campaigns to spread malware
Based on the activity Mandiant has seen, Nobelium actors continue to breach cloud providers and MSPs as a way to gain initial access to their downstream customers' network environments.
In another breach, the attack group used the password-stealing malware CRYPTBOT to steal valid session tokens used for authentication in the Microsoft 365 .
It is worth noting that Nobelium compromises multiple accounts in a single environment, using each of them for separate operations, thus not risking the entire operation in the event of exposure.

A new custom malware “Ceeloader”
Nobelium is known for developing and using custom malware that allows backdoor access to networks, downloading further malware, network reconnaissance, NTLM credential theft, and other malicious behaviors.
Mandiant discovered a new custom downloader called “Ceeloader” written in C and supports executing shellcode payloads directly in memory.
The malware is obfuscated and mixes calls to the Windows API with large blocks of junk code to avoid detection by security software.
Ceeloader communicates via HTTP, while the C2 response is decrypted using AES-256 in CBC mode.
See also: eCommerce servers targeted with malware hiding in Nginx servers
The custom Ceeloader downloader is installed and executed by a Cobalt Strike beacon as required and does not include persistence to allow automatic execution on window startup.
Nobelium has used several custom malware strains in the past, especially during the Solarwinds attacks and in a phishing attack against the United States Agency for International Development (USAID).
Information source: bleepingcomputer.com
