EXECUTIVE SUMMARY:
The Cloud Atlas threat actor group, active for several years, has resurfaced with a refined and regionally targeted campaign against Eastern Europe and Central Asia. The group leveraged spear-phishing emails containing malicious documents that exploit a known vulnerability in Microsoft’s Equation Editor. These documents dynamically retrieve remote RTF templates, which then deploy HTA files containing additional payloads. The infection chain has been customized for each victim, relying on unique HTA scripts and employing techniques such as time-based and IP-restricted access to C2 infrastructure, further complicating detection and analysis. Upon execution, the HTA files deploy the VBShower malware, which in turn installs the secondary PowerShower backdoor. This layered infection chain reflects a mature, stealthy approach with consistent goals: reconnaissance, credential theft, persistence, and data exfiltration. The campaign predominantly targets government, military, telecommunications, energy, and manufacturing sectors, especially in Russia, with isolated activity in other nations including Israel, Moldova, Vietnam, and Turkey.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
The Cloud Atlas threat actor group, active for several years, has resurfaced with a refined and regionally targeted campaign against Eastern Europe and Central Asia. The group leveraged spear-phishing emails containing malicious documents that exploit a known vulnerability in Microsoft’s Equation Editor. These documents dynamically retrieve remote RTF templates, which then deploy HTA files containing additional payloads. The infection chain has been customized for each victim, relying on unique HTA scripts and employing techniques such as time-based and IP-restricted access to C2 infrastructure, further complicating detection and analysis. Upon execution, the HTA files deploy the VBShower malware, which in turn installs the secondary PowerShower backdoor. This layered infection chain reflects a mature, stealthy approach with consistent goals: reconnaissance, credential theft, persistence, and data exfiltration. The campaign predominantly targets government, military, telecommunications, energy, and manufacturing sectors, especially in Russia, with isolated activity in other nations including Israel, Moldova, Vietnam, and Turkey.[emaillocker id="1283"]
The core of the attack hinges on an HTA-based deployment mechanism that extracts multiple VBScript components using NTFS alternate data streams to conceal files within the %APPDATA% path. VBShower comprises several elements: a launcher, an encrypted backdoor, a cleaner, and auxiliary payloads. The launcher decrypts and executes the core backdoor, which maintains persistence via registry keys and fetches additional scripts. These scripts perform reconnaissance, clear traces, and install subsequent malware stages, including VBCloud and PowerShower. VBCloud, operating via scheduled tasks and cloud-based WebDAV infrastructure, exfiltrates documents, system metadata, and even Telegram data through RC4-encrypted ZIP files. PowerShower, on the other hand, focuses on lateral movement and privilege escalation. It downloads PowerShell payloads for Kerberoasting, group enumeration, and password brute-forcing. Notably, PowerShower utilizes the PowerSploit framework and tools like Inveigh for man-in-the-middle credential capture. While VBShower and PowerShower operate on disk and in memory, VBCloud relies on public cloud services as a resilient and anonymized C2 infrastructure, ensuring continued data theft while reducing attribution risk. Collectively, the toolkit demonstrates modular, persistent, and multi-stage capabilities aimed at maintaining long-term access to compromised systems.
Cloud Atlas’s latest campaign illustrates a sophisticated evolution in both toolset and targeting strategy. By blending legacy exploits with updated malware like VBShower, PowerShower, and VBCloud, the group has created a resilient ecosystem capable of sustained espionage. Their focus remains consistent—governmental and strategic sectors—suggesting motives aligned with intelligence gathering rather than financial gain. The reliance on public cloud infrastructure, NTFS ADS obfuscation, and unique scripting per victim showcases a clear emphasis on stealth and operational security. The reuse of known techniques such as script-based payloads and ZIP-based module delivery is balanced with adaptive features like dynamic filename generation and delayed execution via scheduled tasks. Although the infection methodology has changed little since its first documentation, its subtle improvements have rendered it harder to detect and attribute. The campaign’s concentration in Russia, coupled with its use of cloud services and restricted access to payloads, further reinforces its tailored nature.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Initial Access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1059 | Command and Scripting Interpreter | – |
| T1203 | Exploitation for Client Execution | – | |
| T1053.005 | Scheduled Task.Job | Scheduled Task | |
| T1204.002 | User Execution | Malicious File | |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys . Startup Folder |
| Defense Evasion | T1140 | Deobfuscate.Decode Files or Information | – |
| T1564 | Hide Artifacts | – | |
| T1070.004 | Indicator Removal | File Deletion | |
| T1036.005 | Masquerading | Match Legitimate Resource Name or Location | |
| T1027 | Obfuscated Files or Information | – | |
| T1218.005 | System Binary Proxy Execution | Mshta | |
| Credential Access | T1557 | Adversary-in-the-Middle | – |
| T1110.003 | Brute Force | Password Spraying | |
| Discovery | T1087.002 | Account Discovery | Domain Account |
| T1083 | File and Directory Discovery | – | |
| T1201 | Password Policy Discovery | – | |
| T1057 | Process Discovery | – | |
| T1012 | Query Registry | – | |
| T1018 | Remote System Discovery | – | |
| T1082 | System Information Discovery | – | |
| T1016 | System Network Configuration Discovery | – | |
| T1033 | System Owner.User Discovery | – |
[/emaillocker]