APT Group Patches termsrv.dll to Enable Multiple RDP Sessions
ID: 02b6a597-194a-5bc3-bc69-a15a634ae5c1
STIX ID: report--02b6a597-194a-5bc3-bc69-a15a634ae5c1
Feed Name: GBHackers
A Cloud Atlas APT campaign (active 2025–2026) targets government and commercial entities in Russia and Belarus using phishing ZIPs with malicious LNKs and CVE-2018-0802 weaponized documents to execute PowerShell loaders (fixed.ps1) that deploy two backdoors (VBCloud for file theft and PowerShower for reconnaissance and lateral movement). Operators modify termsrv.dll to enable stealthy concurrent RDP sessions, establish persistent reverse tunnels (SSH/RevSocks/Tor), perform Kerberoasting and UAC bypasses for credential theft, and exfiltrate data (including via Google Sheets), demonstrating sophisticated, persistent espionage-focused capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
