VBShower is a Windows VBS-based backdoor associated with the Cloud Atlas espionage group. It functions as a primary launcher and validator component in a multi-stage intrusion chain that commonly begins with spearphishing emails carrying malicious Microsoft Office documents. In documented campaigns, those documents retrieve a remote template and exploit CVE-2018-0802 to execute an HTA payload, which drops the VBShower components to disk. VBShower establishes persistence on the host, restores its autorun mechanism if removed, performs anti-forensic cleanup of Office temporary artifacts, and decrypts and executes its backdoor logic in memory. It communicates over HTTP to obtain additional encrypted VBScript payloads, can execute downloaded VBS content regardless of size, and returns execution output to operator infrastructure. VBShower has been used to install and launch additional Cloud Atlas malware, including PowerShower, VBCloud, and the CloudAtlas backdoor, enabling follow-on reconnaissance, credential theft, file theft, and broader post-exploitation activity. The malware has been observed primarily in campaigns targeting organizations in Eastern Europe and Central Asia, with notable concentration on Russian and Belarusian entities across sectors including government, telecommunications, construction, and industry. VBShower is also described as polymorphic in some campaigns, reflecting efforts to hinder static detection and forensic analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Заражение происходит через фишинговые электронные письма, содержащие вредоносный документ, который использует уязвимость в редакторе формул (CVE-2018-0802) для загрузки и выполнения вредоносного кода. | Вредоносный HTA-файл извлекает и записывает на диск несколько файлов, являющихся частью бэкдора VBShower, который затем загружает другой бэкдор, PowerShower.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Вредоносный HTA-файл извлекает и записывает на диск несколько файлов, являющихся частью бэкдора VBShower, который затем загружает другой бэкдор, PowerShower.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Many examples describe post-intrusion cleanup, anti-forensics, and removal of artifacts such as logs, scripts, malware components, scheduled tasks, registry keys, and temporary files.
VBShower::Cleaner ... removing malicious documents and templates it downloaded from the web during the attack.
Этот шаблон содержит эксплойт для редактора формул, который загружает и выполняет HTML-файл приложения (HTA).
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used earlier in the infection chain; dropped by the malicious HTA and used to load PowerShower.
Custom malware delivered after a malicious Word document loads a remote template from C2 and exploits CVE-2018-0802; VBShower is downloaded using alternate data streams.
VBShower is a backdoor used by the Cloud Atlas threat actor, delivered via phishing documents. It downloads and installs other backdoors and can be used to exfiltrate files and gather information.
Primary launcher backdoor used by Cloud Atlas APT to execute downloaded VB scripts and deploy additional payloads. It communicates with command servers to retrieve and execute scripts for file exfiltration, system enumeration, and credential harvesting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.