CloudAtlas is a cyber-espionage threat actor associated with operations in the broader Russo-Ukrainian and Eastern European region. It has been referenced alongside other long-running actors active in that conflict environment and has been linked with targeted intrusion activity against users in Central Asia and Eastern Europe, as well as activity affecting targets in Russia. Reported victimology includes scientists, researchers, and research scholars, particularly individuals connected to military-themed conferences, indicating an interest in intelligence collection against research and policy-adjacent communities. CloudAtlas is known for spearphishing and document-based intrusion chains that abuse Microsoft Word remote template injection and staged payload delivery. Observed tradecraft includes social-engineering lures themed around military strategy and conference invitations, use of spoofed cloud-hosted infrastructure, and persistence through Word STARTUP templates. Malware associated with CloudAtlas-linked activity has used extensive obfuscation and environmental checks, including browser-artifact validation to evade sandboxing and analysis. CloudAtlas-linked operations have also been associated with cloud-based command-and-control, including use of legitimate online services and web infrastructure for stealth and resilience. Reporting has also connected CloudAtlas-like intrusion patterns to email-based campaigns that deployed the Owowa IIS backdoor against targets in Russia, and to GOFFEE activity that used legitimate utilities and the Mythic agent for reconnaissance, credential access, and follow-on actions in containerized environments. These links are described with moderate confidence and indicate overlap in tradecraft rather than universally confirmed attribution of all related malware families directly to CloudAtlas. Overall, CloudAtlas is best characterized as an espionage-oriented actor that favors phishing-led initial access, stealthy persistence, credential-focused follow-on activity, and abuse of trusted cloud and enterprise services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Using remote template injection and a Google Sheets-based command-and-control channel.
Referenced as a known activity pattern whose email-based intrusion chain was mimicked by another campaign (GOFFEE) targeting Russia.
Referenced as a likely overlapping or related threat actor based on similar targeting, remote-template document delivery, abuse of cloud services, and Microsoft-spoofing domain patterns.
Mentioned only as background example of APT activity in the Russo-Ukrainian conflict region.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.