Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Inception

Also known as: Inception Framework, Cloud Atlas, Clean Ursa, OXYGEN, G0100, ATK116, Blue Odin

Description

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)

TTP Summary

Red October; Cloud Atlas

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

RU
GB
UA

AI Analysis

· 1 week ago

Executive Summary

Inception, also known as Cloud Atlas or Blue Odin, is a cyber espionage group active since at least 2014. The group primarily targets government entities and has been observed in multiple campaigns across regions including Russia, the US, Europe, Asia, Africa, and the Middle East. Inception employs sophisticated tactics, techniques, and procedures (TTPs) to conduct espionage activities, leveraging malware and encrypted communication channels.

Goals & Targeting

Inception's primary motivation appears to be espionage, targeting governmental entities to acquire sensitive information. The group strategically focuses on countries with significant geopolitical influence or advanced technology sectors, such as Russia, the UK, and Ukraine. This suggests a focus on intelligence gathering for strategic or military advantage, aligning with typical nation-state actor behavior.

Enhanced Description

Inception is a persistent cyber threat group specializing in espionage operations. The group has been active since at least 2014 and has targeted government entities, though its activities extend to multiple industries. Inception's campaigns have spanned several regions, including but not limited to Russia, the United States, Europe, Asia, Africa, and the Middle East. The group is known for its use of malicious file-based attacks, symmetric cryptography, and web protocol abuse, as evidenced in reports from Unit 42, Symantec, and Kaspersky. Notable campaigns linked to Inception include 'Red October' and 'Cloud Atlas', which highlight their ability to maintain long-term operations and evade detection.

Key Capabilities

  • Malware development and distribution
  • Spearphishing campaigns
  • Encrypted communication channels
  • File-based attacks (T1204)
  • Symmetric cryptography (T1573)

MITRE ATT&CK Tactics

Exfiltration
Collection
Reconnaissance
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1204.002: Malicious File
T1573.001: Symmetric Cryptography
T1069.002: Domain Groups
T1005: Data from Local System
T1083: File and Directory Discovery
T1102: Web Service
T1218.005: Mshta
T1059.001: PowerShell
T1588.002: Tool
T1203: Exploitation for Client Execution
T1071.001: Web Protocols

Software / Tooling

PowerShower
VBShower
Custom Malware
Encrypted Communication Tools

Campaigns & Victims

Inception's campaigns, including 'Red October' and 'Cloud Atlas', demonstrate a focus on long-term operations with occasional periods of dormancy. The group targets government entities and critical infrastructure sectors, suggesting an interest in high-value intelligence. Their operational tempo is irregular but persistent over years. Notable for their use of encrypted communication channels and file-based attacks, Inception has been observed adapting to avoid detection while maintaining access.

IOC Patterns

  • Spearphishing attacks with malicious files
  • Encrypted/obfuscated communication channels
  • Use of Mshta (T1218.005)
  • Web protocol abuse for C2
  • Staging infrastructure in compromised domains

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems.
  • Monitor and analyze encrypted traffic for anomalies.
  • Conduct regular threat hunting focusing on file-based attacks and web service anomalies.
  • Enhance email filtering to detect spearphishing campaigns.
  • Update and patch systems to mitigate known exploit techniques.

Suggested Tags

APT
Espionage
Government Sector
Geopolitical Targeting

Confidence Assessment

Confidence in Inception's attributes is moderate due to well-documented campaigns and TTPs, but gaps exist regarding exact operational timelines (First Seen/Last Seen) and specific targeting criteria beyond government sectors. Additional intelligence on their toolsets and infrastructure would enhance confidence.

ATT&CK Techniques

Discovery
5 techniques
Execution
4 techniques

Observed Data

No observed data linked yet.

References

  1. Kaspersky Cloud Atlas December 2014 — GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.
  2. Unit 42 Inception November 2018 — Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.
  3. Symantec Inception Framework March 2018 — Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

Intel Summary

22

Techniques

2

Tools

2

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

APT
Government Targeting
Espionage
Government Sector
Geopolitical Targeting

Details

MITRE ID
G0100
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--ead23196-d7b6-4ce6-a124-4ab4b67d81bd
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.