Threat Advisory

Cloud Atlas Launches VBShower and PowerShower in Stealth Campaign

Threat: Phishing Campaign
Threat Actor Name: Cloud Atlas
Threat Actor Type: State-Sponsored
Targeted Region: Eastern Europe, Central Asia
Alias: G0100, Oxygen, Cloud Atlas, Clean Ursa, Inception Framework, Hive0097, Blue Odin, ATK116, The Rocra
Threat Actor Region: Russia
Targeted Sector: Technology & IT, Government & Defense, Energy & Utilities, Telecommunications, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Cloud Atlas threat actor group, active for several years, has resurfaced with a refined and regionally targeted campaign against Eastern Europe and Central Asia. The group leveraged spear-phishing emails containing malicious documents that exploit a known vulnerability in Microsoft’s Equation Editor. These documents dynamically retrieve remote RTF templates, which then deploy HTA files containing additional payloads. The infection chain has been customized for each victim, relying on unique HTA scripts and employing techniques such as time-based and IP-restricted access to C2 infrastructure, further complicating detection and analysis. Upon execution, the HTA files deploy the VBShower malware, which in turn installs the secondary PowerShower backdoor. This layered infection chain reflects a mature, stealthy approach with consistent goals: reconnaissance, credential theft, persistence, and data exfiltration. The campaign predominantly targets government, military, telecommunications, energy, and manufacturing sectors, especially in Russia, with isolated activity in other nations including Israel, Moldova, Vietnam, and Turkey.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Cloud Atlas threat actor group, active for several years, has resurfaced with a refined and regionally targeted campaign against Eastern Europe and Central Asia. The group leveraged spear-phishing emails containing malicious documents that exploit a known vulnerability in Microsoft’s Equation Editor. These documents dynamically retrieve remote RTF templates, which then deploy HTA files containing additional payloads. The infection chain has been customized for each victim, relying on unique HTA scripts and employing techniques such as time-based and IP-restricted access to C2 infrastructure, further complicating detection and analysis. Upon execution, the HTA files deploy the VBShower malware, which in turn installs the secondary PowerShower backdoor. This layered infection chain reflects a mature, stealthy approach with consistent goals: reconnaissance, credential theft, persistence, and data exfiltration. The campaign predominantly targets government, military, telecommunications, energy, and manufacturing sectors, especially in Russia, with isolated activity in other nations including Israel, Moldova, Vietnam, and Turkey.[emaillocker id="1283"]

The core of the attack hinges on an HTA-based deployment mechanism that extracts multiple VBScript components using NTFS alternate data streams to conceal files within the %APPDATA% path. VBShower comprises several elements: a launcher, an encrypted backdoor, a cleaner, and auxiliary payloads. The launcher decrypts and executes the core backdoor, which maintains persistence via registry keys and fetches additional scripts. These scripts perform reconnaissance, clear traces, and install subsequent malware stages, including VBCloud and PowerShower. VBCloud, operating via scheduled tasks and cloud-based WebDAV infrastructure, exfiltrates documents, system metadata, and even Telegram data through RC4-encrypted ZIP files. PowerShower, on the other hand, focuses on lateral movement and privilege escalation. It downloads PowerShell payloads for Kerberoasting, group enumeration, and password brute-forcing. Notably, PowerShower utilizes the PowerSploit framework and tools like Inveigh for man-in-the-middle credential capture. While VBShower and PowerShower operate on disk and in memory, VBCloud relies on public cloud services as a resilient and anonymized C2 infrastructure, ensuring continued data theft while reducing attribution risk. Collectively, the toolkit demonstrates modular, persistent, and multi-stage capabilities aimed at maintaining long-term access to compromised systems.

Cloud Atlas’s latest campaign illustrates a sophisticated evolution in both toolset and targeting strategy. By blending legacy exploits with updated malware like VBShower, PowerShower, and VBCloud, the group has created a resilient ecosystem capable of sustained espionage. Their focus remains consistent—governmental and strategic sectors—suggesting motives aligned with intelligence gathering rather than financial gain. The reliance on public cloud infrastructure, NTFS ADS obfuscation, and unique scripting per victim showcases a clear emphasis on stealth and operational security. The reuse of known techniques such as script-based payloads and ZIP-based module delivery is balanced with adaptive features like dynamic filename generation and delayed execution via scheduled tasks. Although the infection methodology has changed little since its first documentation, its subtle improvements have rendered it harder to detect and attribute. The campaign’s concentration in Russia, coupled with its use of cloud services and restricted access to payloads, further reinforces its tailored nature.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Initial Access T1566.001 Phishing Spearphishing Attachment
Execution T1059 Command and Scripting Interpreter
T1203 Exploitation for Client Execution
T1053.005 Scheduled Task.Job Scheduled Task
T1204.002 User Execution Malicious File
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys . Startup Folder
Defense Evasion T1140 Deobfuscate.Decode Files or Information
T1564 Hide Artifacts
T1070.004 Indicator Removal File Deletion
T1036.005 Masquerading Match Legitimate Resource Name or Location
T1027 Obfuscated Files or Information
T1218.005 System Binary Proxy Execution Mshta
Credential Access T1557 Adversary-in-the-Middle
T1110.003 Brute Force Password Spraying
Discovery T1087.002 Account Discovery Domain Account
T1083 File and Directory Discovery
T1201 Password Policy Discovery
T1057 Process Discovery
T1012 Query Registry
T1018 Remote System Discovery
T1082 System Information Discovery
T1016 System Network Configuration Discovery
T1033 System Owner.User Discovery

 

[/emaillocker]
crossmenu