PowerShower is a PowerShell-based backdoor associated with the Cloud Atlas espionage group. It has been used as a second-stage implant in multi-step intrusion chains that begin with phishing, including malicious shortcut files in archives and malicious Office documents exploiting Equation Editor vulnerabilities such as CVE-2018-0802. In Cloud Atlas operations, earlier stages including VBShower or related loaders deploy PowerShower alongside other tooling such as VBCloud, with PowerShower serving primarily as a reconnaissance, credential-access, and lateral-movement component rather than a pure document stealer.
On compromised Windows systems, PowerShower can identify the current user, enumerate running processes, administrator groups, domain controllers, and other Active Directory or host information, and probe the local network to support further intrusion activity. Reported tasking includes downloading and executing additional PowerShell scripts from command-and-control infrastructure, conducting Kerberoasting attacks, performing dictionary-style attacks against user accounts, and using credential-interception tooling in some Cloud Atlas campaigns. It has also been observed using a document-stealer module to collect recently modified office and text documents, compress them, and exfiltrate them over its existing command-and-control channel.
PowerShower incorporates defense-evasion measures. It modifies the Windows environment so future PowerShell windows are positioned off-screen, reducing user visibility, and removes registry artifacts left by parts of the dropper chain. Its command-and-control traffic has been observed using Base64 encoding. In later Cloud Atlas activity, PowerShower also acted as a downloader for additional payloads, including a Golang backdoor known as CloudAtlasGo.
Victimology tied to the broader Cloud Atlas campaigns using PowerShower has centered on government, diplomatic, and other organizations in Russia, Belarus, and parts of Eastern Europe and Central Asia, consistent with long-running espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Заражение происходит через фишинговые электронные письма, содержащие вредоносный документ, который использует уязвимость в редакторе формул (CVE-2018-0802) для загрузки и выполнения вредоносного кода.
Previously, Cloud Atlas dropped its “validator” implant named “PowerShower” directly, after exploiting the Microsoft Equation vulnerability (CVE-2017-11882) mixed with CVE-2018-0802.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
В большинстве случаев злоумышленники ограничивались бэкдорами VBShower и PowerShower... Однако в начале мая 2026 года... бэкдор PowerShower загружал исполняемый файл, написанный на Golang... Этот зловред мы назвали CloudAtlasGo.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Bisonal has deleted Registry keys to clean up its prior activity ... FIN8 has deleted Registry keys during post compromise cleanup activities ... SUNBURST ... deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
We also observed the use of PowerShell Inveigh, a machine-in-the-middle attack utility used in penetration testing. Inveigh is used for data packet spoofing attacks, and collecting hashes and credentials both by intercepting packets and by using protocol-specific sockets.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
PowerShower probes the local network and facilitates further infiltration.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
PowerShower probes the local network and facilitates further infiltration.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Gets information about the file names and sizes in the following folders: %AppData%; %AllUsersProfile%; ...
Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP... Tomiris can upload files matching a hardcoded set of extensions... PowerShower packed and exfiltrated .txt, .pdf, .xls or .doc files smaller than 5MB modified during the past two days.
We also observed the use of PowerShell Inveigh, a machine-in-the-middle attack utility used in penetration testing. Inveigh is used for data packet spoofing attacks, and collecting hashes and credentials both by intercepting packets and by using protocol-specific sockets.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used by Cloud Atlas for network reconnaissance, credential access, and theft of files and documents; in this campaign it also loads CloudAtlasGo.
A reconnaissance tool used by Cloud Atlas during post-compromise activity, delivered alongside VBCloud.
Backdoor focused on network reconnaissance and lateral movement. It can collect information on running processes, administrator groups, and domain controllers, download and execute PowerShell scripts from C2, perform Kerberoasting, and load an additional credential-theft script that copies SAM and SECURITY hives using a shadow copy and uses fodhelper.exe for UAC bypass.
PowerShower is a backdoor used as a secondary payload by Cloud Atlas, capable of retrieving and executing additional payloads from a remote server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.