logo

APT Group Patches termsrv.dll to Enable Multiple RDP Sessions

ID: 02b6a597-194a-5bc3-bc69-a15a634ae5c1

STIX ID: report--02b6a597-194a-5bc3-bc69-a15a634ae5c1

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Mayura Kathir

...
...

A Cloud Atlas APT campaign (active 2025–2026) targets government and commercial entities in Russia and Belarus using phishing ZIPs with malicious LNKs and CVE-2018-0802 weaponized documents to execute PowerShell loaders (fixed.ps1) that deploy two backdoors (VBCloud for file theft and PowerShower for reconnaissance and lateral movement). Operators modify termsrv.dll to enable stealthy concurrent RDP sessions, establish persistent reverse tunnels (SSH/RevSocks/Tor), perform Kerberoasting and UAC bypasses for credential theft, and exfiltrate data (including via Google Sheets), demonstrating sophisticated, persistent espionage-focused capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.