logo

Cloud Atlas activity in the first half of 2025: what changed

ID: 2251e258-2ffa-58d3-8c47-44f743d7f440

STIX ID: report--2251e258-2ffa-58d3-8c47-44f743d7f440

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-04-29

Author: Kaspersky

...
...

This report analyzes Cloud Atlas APT operations in the first half of 2025: actors use phishing documents that exploit CVE-2018-0802 to fetch an HTA and execute a multi-stage chain (VBShower → VBCloud/PowerShower/CloudAtlas). The document describes each implant’s installation and capabilities (remote command execution, file and credential exfiltration, plugin architecture), cloud-based WebDAV command-and-control, targeted sectors in Russia and Belarus, and provides detailed IoCs (hashes, domains, file paths) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.