CLOUD ATLAS
THREAT CAMPAIGN: CLOUD ATLAS APT MODULAR MALWARE OPERATIONS
■ Cloud Atlas is an APT first observed around 2014, known for long-term, targeted cyber-espionage operations. It typically focuses on government, research, and high-value targets, especially in Eastern Europe and Central Asia.
■ In the first half of 2025, Cloud Atlas continued to rely on spear-phishing emails with malicious document attachments that exploit legacy Microsoft Office vulnerabilities (e.g., CVE-2018-0802) to execute malicious content and start the infection chain.
■ Once executed, the phishing chain drops a series of modular implants.
This is How they do it
■ VBShower: Initiates infection, collects system information, and deploys secondary payloads.
■ VBCloud: Acts as a flexible backdoor with potential plug-ins for data exfiltration.
■ PowerShower: Another backdoor variant providing additional command and control functionality.
■ CloudAtlas implant: The core payload with plugins for password theft and information collection.
The campaign’s targets continue to skew toward entities in Russia, Belarus, and neighboring states, consistent with prior campaigns attributed to this actor.
Source: SECURELIST
🔗 https://securelist.com/cloud-atlas-h1-2025-campaign/118517/
All threat research, exploit analysis, and adversary technique assessments discussed in this article have been conducted in isolated, air-gapped laboratory environments with proper authorization and security controls.


