Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code
ID: 28f04286-7efe-500c-a914-98e7430f5441
STIX ID: report--28f04286-7efe-500c-a914-98e7430f5441
Feed Name: cybersecurityNews.com
Cloud Atlas conducted a multi-stage cyber-espionage campaign across Eastern Europe and Central Asia in H1 2025, leveraging CVE-2018-0802 in malicious Word/RTF documents to deploy a suite of backdoors (VBShower, PowerShower, VBCloud, CloudAtlas). The intrusion chain uses VBS/HTML Application payloads, RC4-encrypted payloads, scheduled tasks for persistence, and WebDAV/cloud services for encrypted C2 and data exfiltration, targeting telecommunications, construction, government, and industrial sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
