logo

Cloud Atlas seen using a new tool in its attacks

ID: 86f0a071-2959-5665-8c19-e0be8395121f

STIX ID: report--86f0a071-2959-5665-8c19-e0be8395121f

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2024-12-23

Date Updated: 2026-04-29

Author: Oleg Kupreev

...
...

Cloud Atlas, an APT active since 2014 and active in 2023–2024, uses phishing emails and an RTF/Formula Editor (CVE-2018-0802) exploit to download an HTA dropper that installs VBShower. VBShower loads additional modules (PowerShower, VBCloud) which perform network discovery, credential attacks (Kerberoasting, Inveigh), and targeted file exfiltration to public WebDAV cloud storage; the report includes detailed technical analysis, sample paths, payload behaviors and numerous IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.