Also known as: Inception Framework, Cloud Atlas, Clean Ursa, OXYGEN, G0100, ATK116, Blue Odin
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)
Red October; Cloud Atlas
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Inception, also known as Cloud Atlas or Blue Odin, is a cyber espionage group active since at least 2014. The group primarily targets government entities and has been observed in multiple campaigns across regions including Russia, the US, Europe, Asia, Africa, and the Middle East. Inception employs sophisticated tactics, techniques, and procedures (TTPs) to conduct espionage activities, leveraging malware and encrypted communication channels.
Goals & Targeting
Inception's primary motivation appears to be espionage, targeting governmental entities to acquire sensitive information. The group strategically focuses on countries with significant geopolitical influence or advanced technology sectors, such as Russia, the UK, and Ukraine. This suggests a focus on intelligence gathering for strategic or military advantage, aligning with typical nation-state actor behavior.
Enhanced Description
Inception is a persistent cyber threat group specializing in espionage operations. The group has been active since at least 2014 and has targeted government entities, though its activities extend to multiple industries. Inception's campaigns have spanned several regions, including but not limited to Russia, the United States, Europe, Asia, Africa, and the Middle East. The group is known for its use of malicious file-based attacks, symmetric cryptography, and web protocol abuse, as evidenced in reports from Unit 42, Symantec, and Kaspersky. Notable campaigns linked to Inception include 'Red October' and 'Cloud Atlas', which highlight their ability to maintain long-term operations and evade detection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Inception's campaigns, including 'Red October' and 'Cloud Atlas', demonstrate a focus on long-term operations with occasional periods of dormancy. The group targets government entities and critical infrastructure sectors, suggesting an interest in high-value intelligence. Their operational tempo is irregular but persistent over years. Notable for their use of encrypted communication channels and file-based attacks, Inception has been observed adapting to avoid detection while maintaining access.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Inception's attributes is moderate due to well-documented campaigns and TTPs, but gaps exist regarding exact operational timelines (First Seen/Last Seen) and specific targeting criteria beyond government sectors. Additional intelligence on their toolsets and infrastructure would enhance confidence.
Red October
Cloud Atlas
No observed data linked yet.
22
Techniques
2
Tools
2
Campaigns
40
IOCs
0
Observed Data
9
Tactics