Cloud Atlas' Spear-Phishing Attacks Target Russian Agro and Research Companies
ID: f6b9fc09-cbc6-5f70-bdf2-1f5b780817ab
STIX ID: report--f6b9fc09-cbc6-5f70-bdf2-1f5b780817ab
Feed Name: The Hacker News
Cloud Atlas, an APT active since at least 2014, is conducting large-scale spear-phishing campaigns against Russian organizations using RTF/RTF-template injection to exploit CVE-2017-11882 and deliver multi-stage payloads (obfuscated HTA → VBS → PowerShower backdoor and DLLs). The report also highlights related activity by an actor labeled Hellhounds using Decoy Dog (a modified Pupy RAT) that includes exfiltration/telemetry mechanisms, demonstrating sustained, targeted cyber-espionage operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
