Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors AtlasCross

Description

NSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this finding through extensive research, they confirmed two new Trojan horse programs and many rare attack techniques and tactics. NSFOCUS Security Labs believes that this new attack process comes from a new APT attacker, who has a high technical level and cautious attack attitude. The phishing attack activity captured this time is part of the attacker’s targeted strike on specific targets and is its main means to achieve in-domain penetration. NSFOCUS Security Labs validated the high-level threat attributes of AtlasCross in terms of development technology and attack strategy through an in-depth analysis of its attack metrics. At this current stage, AtlasCross has a relatively limited scope of activity, primarily focusing on targeted attacks against specific hosts within a network domain. However, the attack processes they employ are highly robust and mature. NSFOCUS Security Labs deduce that this attacker is highly likely to deploy this attack process into larger-scale network attack operations.

AI Analysis

· 1 week ago

Executive Summary

AtlasCross is a suspected advanced persistent threat (APT) group identified by NSFOCUS Security Labs through novel phishing campaigns and sophisticated attack techniques. The actor demonstrates high technical proficiency and cautious operational behavior, targeting specific hosts within restricted network domains. While currently active on a limited scale, AtlasCross poses significant risks due to its robust attack processes and potential for larger-scale operations.

Goals & Targeting

AtlasCross exhibits a strategic focus on achieving long-term network penetration through targeted attacks. Its primary goal appears to be gaining unauthorized access to specific hosts within a network domain, possibly to establish persistence and lateral movement capabilities. The actor's cautious approach suggests it is targeting high-value assets or sensitive information within sectors where limited visibility would provide strategic advantages. The choice of phishing as the initial attack vector indicates an intent to compromise human factors while maintaining operational stealth to avoid detection. While the exact motivation remains unclear, the combination of technical proficiency and targeted tactics aligns with APT behavior typically linked to state-sponsored espionage or financial gain.

Enhanced Description

AtlasCross, emerging from recent threat-hunting efforts by NSFOCUS Security Labs, represents a new APT group leveraging sophisticated phishing tactics and custom malware. The actor was identified through the deployment of two novel Trojan horse programs and highly refined attack methodologies. These techniques highlight a high level of technical expertise and strategic focus on achieving deep network penetration. AtlasCross primarily employs phishing campaigns using macro-laced Office documents as the initial infection vector, indicative of a methodical approach to compromise specific targets. The actor's cautious operational style suggests it aims for persistence within targeted networks rather than immediate disruption, aligning with typical APT behavior. While its scope appears limited at present, the maturity of its attack processes raises concerns about potential future expansion into broader campaigns. NSFOCUS Labs has not observed significant campaign activity from AtlasCross to date, but its high technical threshold and strategic targeting underscore the need for vigilance among potential victims.

Key Capabilities

  • Development of custom malware
  • Phishing campaigns using macro-laced documents
  • Sophisticated attack techniques for network traversal
  • High level of operational caution to avoid detection
  • Targeted domain penetration strategies

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access

Software / Tooling

Custom Trojan horse programs
HTTP-based command and control (C2) communication
Lateral movement tools

Campaigns & Victims

AtlasCross has demonstrated limited but highly sophisticated campaign activity, focusing on targeted attacks rather than widespread distribution. Its primary method involves phishing campaigns to compromise specific hosts within a network domain, suggesting an interest in long-term access and persistence. NSFOCUS Security Labs has not observed significant expansion of its operations to date; however, the actor's highly refined attack processes indicate potential for more extensive campaigns. The cautious operational style suggests AtlasCross may be preparing for larger-scale or high-value targets, which could pose risks to sectors requiring stringent network security.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • HTTP-based command and control communication
  • Custom malware signatures
  • Network activity indicative of persistent threat actors

Recommended Actions

  • Implement robust email filtering to detect phishing attempts
  • Monitor for unusual network activity using advanced SIEM tools
  • Conduct regular user training on identifying suspicious emails
  • Deploy endpoint detection and response (EDR) solutions
  • Segment networks to limit lateral movement potential

Suggested Tags

APT
espionage
spear-phishing
custom-malware

Confidence Assessment

Moderate confidence in the identification of AtlasCross as a new APT group based on NSFOCUS Security Labs' analysis. Key gaps include limited historical campaign data and an unclear primary motivation or broader targeting strategy. Additional intelligence on associated tools, infrastructure, and specific targets would enhance understanding of its capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Phishing
espionage
spear-phishing
custom-malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.