PULSE NAME
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
WHITE Inception Framework AlienVault 2026-05-22 Modified: 2026-05-25
115
IOCs
HIGH VOLUME
Cloud Atlas APT group targeted government organizations and commercial companies in Russia and Belarus during late 2025 and early 2026, employing phishing campaigns with malicious ZIP archives containing LNK shortcuts. The attackers deployed multiple backdoors including VBCloud for file theft and PowerShower for network reconnaissance. New tools identified include PowerCloud, which exfiltrates data to Google Sheets, and browser checker utilities. The group established persistence through reverse SSH tunnels, patched OpenSSH binaries, ReverseSocks, and Tor networking. Initial infection vectors included malicious shortcuts executing PowerShell scripts and exploiting CVE-2018-0802 in Microsoft Office. The attackers performed credential theft, RDP manipulation via termsrv.dll patching, and lateral movement across networks while maintaining multiple backup control channels.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
PowerCloud VBCloud PowerShower - S0441 ReverseSocks PhantomHeart ValleyRAT ABCDoor NetSupport RAT
Indicators of Compromise (15 / 115 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 185.22.154.73 2026-05-22
IPv4 185.250.181.207 2026-05-22
IPv4 194.102.104.207 2026-05-22
IPv4 194.87.196.163 2026-05-22
IPv4 195.58.49.9 2026-05-22
IPv4 37.228.129.224 2026-05-22
IPv4 45.87.219.116 2026-05-22
IPv4 46.17.44.125 2026-05-22
IPv4 46.17.44.212 2026-05-22
IPv4 46.17.45.49 2026-05-22
IPv4 46.17.45.56 2026-05-22
IPv4 5.181.21.75 2026-05-22
IPv4 81.30.105.71 2026-05-22
IPv4 93.125.114.193 2026-05-22
IPv4 93.125.114.57 2026-05-22