The Cloud Atlas modular backdoor is a custom, second-stage malware used by the Cloud Atlas (aka Inception) cyber-espionage group. It is deployed following initial compromise via spear-phishing campaigns that leverage malicious Office documents exploiting vulnerabilities such as CVE-2017-11882 and CVE-2018-0802. The infection chain typically involves polymorphic HTA and VBS scripts (VBShower) and PowerShell-based implants (PowerShower) for initial validation, persistence, and deployment of the modular backdoor. The modular backdoor itself communicates via Webdav to a cloud storage service for command-and-control. It is designed for data exfiltration, reconnaissance, and credential theft, and is notable for its stability, having remained unchanged for at least five years. The malware is used exclusively by Cloud Atlas, which targets governmental and industrial entities, particularly in Russia, Central Asia, and conflict regions of Ukraine. The group employs custom malware rather than open-source implants, and their infection chains are designed to evade detection and forensic analysis through polymorphism and unique code generation per victim.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.