/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Halcyon: Cloudzy, a Wyoming-registered web hosting company likely operating out of Tehran, is acting as a command-and-control provider for state-backed hackers

A little-known cloud company provided web hosting and internet services to more than two dozen different state-sponsored hacking groups …

TechCrunch Carly Page

Context & Ripple Effects

Earlier coverage showed state-backed operations exploiting cloud and internet infrastructure at scale, including Cloud Hopper’s penetration of more than a dozen cloud providers and Lebanese Cedar’s compromise of unpatched telecom and ISP servers.

The Cloudzy allegation matters because it moves attention from compromised infrastructure to a hosting provider allegedly serving as operational infrastructure for numerous state-sponsored groups. Its Wyoming registration and likely Tehran-based operations underline the difficulty of tying hosting accountability to a single jurisdiction.

First-order effects

  • Cloudzy faces heightened scrutiny over its hosting and command-and-control services, while the alleged state-backed customers risk exposure of infrastructure used to manage operations.
  • Defenders can treat Cloudzy-linked infrastructure as a higher-priority lead for blocking, investigation, and threat hunting, subject to validation of the report’s indicators.

Second-order effects

  • Hosting providers and resellers have added incentive to review customer verification, abuse reporting, and command-and-control detection where corporate registration and operational location diverge.
  • Security teams may increasingly evaluate hosting provenance alongside technical indicators, rather than treating a U.S. registration as a meaningful proxy for operational risk.

Third-order effects

  • If similar cases persist, internet infrastructure governance will be shaped less by where a company is incorporated and more by who operates it, how it is monitored, and whether abuse can be attributed across borders.
  • The pattern points to a harder divide between legitimate hosting neutrality and infrastructure that repeatedly enables state-linked operations, potentially increasing pressure for stronger provider accountability.

The trend: State-backed cyber operations are increasingly making hosting and cloud infrastructure itself a contested layer of geopolitical security.

Discussion

  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    Wild research from a cybersecurity firm, which claims a U.S. registered cloud host called Cloudzy is actually a cutout for a Tehran, Iran-based cloud host.  The researchers say Cloudzy has been used by at least two dozen of nation-state hackers and spyware operators (including Ca…
  • @aliwolfpr Ali Wolf✨ on x
    “In a report released on Tuesday, @HalcyonAi said it had identified that the U.S.-registered company Cloudzy was “knowingly or unwittingly” acting as a command-and-control provider (C2P) to well-known state-sponsored hacking groups.” More from @CarlyPage_ on @TechCrunch below:
  • @snlyngaas Sean Lyngaas on x
    “Cloudzy CEO Hannan Nozari ... estimated only 2% [of the firm's clients] were malicious. In an exchange over LinkedIn, Nozari told Reuters: ‘If you are a knife factory, are you responsible if someone misuses the knife?’” https://www.reuters.com/...
  • @kaylintrychon Kaylin Trychon on x
    Sheeeeeeesh. “Researchers at Texas-based Halcyon said a company called Cloudzy had been leasing server space and reselling it to no fewer than 17 different state-sponsored hacking groups from China, Russia, Iran, North Korea, India, Pakistan and Vietnam.”
  • @therecord_media @therecord_media on x
    Known as a ‘Command-and-Control Provider’, Cloudzy allegedly supports malicious actors such as #BlackBasta and Royal ransomware gangs, and state-backed hackers from North Korea, Russia, China, India, Pakistan, and Vietnam.
  • @cthulhu_answers @cthulhu_answers on x
    A little-known cloud company provided web hosting and internet services to more than two dozen different state-sponsored hacking groups and commercial spyware operators, according to researchers. Halcyon said that the two-dozen groups that rely on Cloudzy include the...
  • @malwarejake Jake Williams on x
    Great reporting by @Bing_Chris and @RaphaelSatter on what is clearly some shady business practices. That the Cloudzy CEO passed responsibility for malicious activity to clients and said only 2% of activity on the site was malicious is not surprising. 1/2 https://www.reuters.com/.…
  • @carlypage_ Carly Page on x
    Researchers at @HalcyonAi claim a little-known, US-registered cloud company provided hosting services to more than two dozen different state-sponsored hacking groups and commercial spyware operators https://techcrunch.com/...
  • r/technology r on reddit
    Cloud company assisted 17 different government hacking groups -US researchers