Cloud Atlas, also known as Inception and Inception Framework, is a long-running cyber-espionage threat actor active since at least 2014. The group is primarily associated with espionage operations targeting organizations in Eastern Europe and Central Asia, with recurring focus on government, diplomatic, and defense-related entities, including defense-industrial organizations. Reporting also indicates activity against counterparties and supply-chain-adjacent organizations as part of business email compromise-enabled intrusion chains. Cloud Atlas is known for spearphishing-led initial access, including malicious attachments and lure documents crafted for specific victims. A recurring infection chain has used exploitation of CVE-2018-0802 in Microsoft Equation Editor to transition from a phishing document to follow-on stages such as HTA, VBS, and PowerShell payloads. The actor has also used ZIP archives and malicious shortcut files, and has sent BEC-style messages from compromised organizations to trusted counterparties after preparing infrastructure over extended periods. The group’s malware ecosystem has evolved over time. Earlier and mid-period operations prominently featured VBShower and PowerShower, used for staging, persistence, reconnaissance, credential theft, and document collection. Cloud Atlas has also deployed VBCloud and PowerCloud, including variants that used public cloud storage and WebDAV-based channels for command and control and task retrieval. In 2026, the actor was observed introducing CloudAtlasGo, a Golang backdoor that marked a shift from predominantly VBS and PowerShell tooling to a compiled implant using WebRTC for command and control, with cloud services used for signaling exchange. CloudAtlasGo supports command execution, file transfer, proxying, port forwarding, and network reconnaissance, and includes anti-analysis checks. Observed tradecraft includes persistence via Windows Registry Run keys and scheduled tasks; extensive host reconnaissance covering operating system, hardware, processes, files, directories, and network environment; collection of documents and other locally stored data; and theft of browser credentials, passwords, and sessions. Cloud Atlas has also used open-source credential theft tooling such as LaZagne. Its tooling has employed encrypted or obfuscated payloads and configuration data, including AES and RC4, to hinder analysis and detection. For command and control, Cloud Atlas has used HTTP, HTTPS, and WebDAV, and more recently WebRTC-based communications. The actor has also demonstrated layered access and persistence techniques, including reverse tunnels, proxy tooling, and modifications that facilitate covert remote access while minimizing disruption to the legitimate user. Overall, Cloud Atlas is a mature espionage actor distinguished by tailored phishing, modular Windows malware, cloud-service abuse, credential theft, and steady adaptation of its command-and-control architecture.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Заражение происходит через фишинговые электронные письма, содержащие вредоносный документ, который использует уязвимость в редакторе формул (CVE-2018-0802) для загрузки и выполнения вредоносного кода.
In August 2014, some of our users observed targeted attacks with a variation of CVE-2012-0158 and an unusual set of malware.
Previously, Cloud Atlas dropped its “validator” implant named “PowerShower” directly, after exploiting the Microsoft Equation vulnerability (CVE-2017-11882) mixed with CVE-2018-0802.
Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
181 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud Atlas is conducting phishing-led intrusions delivering a new Golang backdoor, CloudAtlasGo, while continuing to use earlier tooling such as VBShower and PowerShower. The group uses malicious documents exploiting Equation Editor flaws, then performs reconnaissance, credential theft, file theft, command execution, file transfer, proxying, and network scanning. The new backdoor uses WebRTC for C2 and cloud services such as Trello, as well as WebDAV or SFTP, for SDP signaling.
APT targeting defense-industrial and government entities using business email compromise from compromised counterparties and long pre-attack infrastructure preparation.
Mentioned only as a comparative example of another group with similar execution chains.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.