DriftingCloud
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:53:17
Targeted industries: government-and-public-sector financial-services defense-and-aerospace technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:au country_code:jp
Context
DriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or acquiring zero-day exploits to gain unauthorized access to target networks. Compromising gateway devices is a common tactic used by DriftingCloud, making network monitoring solutions crucial for detecting their attacks.
Reports & references
- Trend Micro — Supply Chain Attack Targeting Pakistani Government Delivers Shad (report)
- socradar.io — Driftingcloud Apt Group Exploits Zero Day In Sophos Firewall (report)
- volexity.com — Driftingcloud Zero Day Sophos Firewall Exploitation And An Insidious Breach (report)