logo

Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code

ID: 28f04286-7efe-500c-a914-98e7430f5441

STIX ID: report--28f04286-7efe-500c-a914-98e7430f5441

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cloud Atlas conducted a multi-stage cyber-espionage campaign across Eastern Europe and Central Asia in H1 2025, leveraging CVE-2018-0802 in malicious Word/RTF documents to deploy a suite of backdoors (VBShower, PowerShower, VBCloud, CloudAtlas). The intrusion chain uses VBS/HTML Application payloads, RC4-encrypted payloads, scheduled tasks for persistence, and WebDAV/cloud services for encrypted C2 and data exfiltration, targeting telecommunications, construction, government, and industrial sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.