Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

tenkoff.org

TLP:CLEAR
Active

Domain

Description

Cloud Atlas APT group targeted government organizations and commercial companies in Russia and Belarus during late 2025 and early 2026, employing phishing campaigns with malicious ZIP archives containing LNK shortcuts. The attackers deployed multiple backdoors including VBCloud for file theft and PowerShower for network reconnaissance. New tools identified include PowerCloud, which exfiltrates data to Google Sheets, and browser checker utilities. The group established persistence through reverse SSH tunnels, patched OpenSSH binaries, ReverseSocks, and Tor networking. Initial infection vectors included malicious shortcuts executing PowerShell scripts and exploiting CVE-2018-0802 in Microsoft Office. The attackers performed credential theft, RDP manipulation via termsrv.dll patching, and lateral movement across networks while maintaining multiple backup control channels.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:41
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of tenkoff.org

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.