logo

Cloud Atlas' Spear-Phishing Attacks Target Russian Agro and Research Companies

ID: f6b9fc09-cbc6-5f70-bdf2-1f5b780817ab

STIX ID: report--f6b9fc09-cbc6-5f70-bdf2-1f5b780817ab

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2023-12-25

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Cloud Atlas, an APT active since at least 2014, is conducting large-scale spear-phishing campaigns against Russian organizations using RTF/RTF-template injection to exploit CVE-2017-11882 and deliver multi-stage payloads (obfuscated HTA → VBS → PowerShower backdoor and DLLs). The report also highlights related activity by an actor labeled Hellhounds using Decoy Dog (a modified Pupy RAT) that includes exfiltration/telemetry mechanisms, demonstrating sustained, targeted cyber-espionage operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.