Cloud Atlas seen using a new tool in its attacks
ID: 86f0a071-2959-5665-8c19-e0be8395121f
STIX ID: report--86f0a071-2959-5665-8c19-e0be8395121f
Feed Name: Securelist by Kaspersky
Cloud Atlas, an APT active since 2014 and active in 2023–2024, uses phishing emails and an RTF/Formula Editor (CVE-2018-0802) exploit to download an HTA dropper that installs VBShower. VBShower loads additional modules (PowerShower, VBCloud) which perform network discovery, credential attacks (Kerberoasting, Inveigh), and targeted file exfiltration to public WebDAV cloud storage; the report includes detailed technical analysis, sample paths, payload behaviors and numerous IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
