Halcyon: Cloudzy, a Wyoming-registered web hosting company likely operating out of Tehran, is acting as a command-and-control provider for state-backed hackers
A little-known cloud company provided web hosting and internet services to more than two dozen different state-sponsored hacking groups …
The Cloudzy allegation matters because it moves attention from compromised infrastructure to a hosting provider allegedly serving as operational infrastructure for numerous state-sponsored groups. Its Wyoming registration and likely Tehran-based operations underline the difficulty of tying hosting accountability to a single jurisdiction.
First-order effects
Cloudzy faces heightened scrutiny over its hosting and command-and-control services, while the alleged state-backed customers risk exposure of infrastructure used to manage operations.
Defenders can treat Cloudzy-linked infrastructure as a higher-priority lead for blocking, investigation, and threat hunting, subject to validation of the report’s indicators.
Second-order effects
Hosting providers and resellers have added incentive to review customer verification, abuse reporting, and command-and-control detection where corporate registration and operational location diverge.
Security teams may increasingly evaluate hosting provenance alongside technical indicators, rather than treating a U.S. registration as a meaningful proxy for operational risk.
Third-order effects
If similar cases persist, internet infrastructure governance will be shaped less by where a company is incorporated and more by who operates it, how it is monitored, and whether abuse can be attributed across borders.
The pattern points to a harder divide between legitimate hosting neutrality and infrastructure that repeatedly enables state-linked operations, potentially increasing pressure for stronger provider accountability.
The trend: State-backed cyber operations are increasingly making hosting and cloud infrastructure itself a contested layer of geopolitical security.
Wild research from a cybersecurity firm, which claims a U.S. registered cloud host called Cloudzy is actually a cutout for a Tehran, Iran-based cloud host. The researchers say Cloudzy has been used by at least two dozen of nation-state hackers and spyware operators (including Ca…
“In a report released on Tuesday, @HalcyonAi said it had identified that the U.S.-registered company Cloudzy was “knowingly or unwittingly” acting as a command-and-control provider (C2P) to well-known state-sponsored hacking groups.” More from @CarlyPage_ on @TechCrunch below:
“Cloudzy CEO Hannan Nozari ... estimated only 2% [of the firm's clients] were malicious. In an exchange over LinkedIn, Nozari told Reuters: ‘If you are a knife factory, are you responsible if someone misuses the knife?’” https://www.reuters.com/...
Sheeeeeeesh. “Researchers at Texas-based Halcyon said a company called Cloudzy had been leasing server space and reselling it to no fewer than 17 different state-sponsored hacking groups from China, Russia, Iran, North Korea, India, Pakistan and Vietnam.”
Known as a ‘Command-and-Control Provider’, Cloudzy allegedly supports malicious actors such as #BlackBasta and Royal ransomware gangs, and state-backed hackers from North Korea, Russia, China, India, Pakistan, and Vietnam.
A little-known cloud company provided web hosting and internet services to more than two dozen different state-sponsored hacking groups and commercial spyware operators, according to researchers. Halcyon said that the two-dozen groups that rely on Cloudzy include the...
Great reporting by @Bing_Chris and @RaphaelSatter on what is clearly some shady business practices. That the Cloudzy CEO passed responsibility for malicious activity to clients and said only 2% of activity on the site was malicious is not surprising. 1/2 https://www.reuters.com/.…
Researchers at @HalcyonAi claim a little-known, US-registered cloud company provided hosting services to more than two dozen different state-sponsored hacking groups and commercial spyware operators https://techcrunch.com/...