216.73.217.80

Cloud Atlas activity in the first half of 2025: what changed

· Published 20/12/2025 00:17 · Modified 21/12/2025 23:08

Export JSON

Essential information

Published
20/12/2025 00:17
Modified
21/12/2025 23:08
Tags
2025-12-20 CVE-2018-0802 apt central asia cloud c2 cloudatlas eastern europe phishing powershower vbcloud vbshower
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 4 malware, 25 others

Description

The Cloud Atlas group continues to target countries in and using emails with malicious attachments exploiting . The infection chain now includes several implants: , , , and . New and updated components are described, including payloads for file exfiltration, credential stealing, and system information gathering. The backdoors use cloud services for command and control. Targets were identified in Russia and Belarus across telecommunications, construction, government, and manufacturing sectors. The group has been active for over 10 years and continues to expand its capabilities.

External references