VBCloud is a Windows backdoor used by the Cloud Atlas espionage group as part of multi-stage intrusion chains against organizations primarily in Eastern Europe and Central Asia, with recent victimology heavily concentrated in Russia and Belarus and including government, diplomatic, telecommunications, construction, industrial, and other commercial entities. It is typically deployed after initial compromise through phishing-delivered Office documents exploiting CVE-2018-0802 or through malicious shortcut and PowerShell-based chains, often alongside other Cloud Atlas tools such as VBShower and PowerShower.
VBCloud is commonly implemented as a Visual Basic Script launcher paired with an encrypted backdoor body that is decrypted and executed in memory, with RC4 used in observed variants. The malware maintains persistence through mechanisms including scheduled tasks and registry autoruns, and it has been installed under masquerading directories within shared Windows data locations. Cloud Atlas has used VBCloud as a modular post-compromise implant that can receive and execute additional scripts or payloads, collect host and system information, and support encrypted communications through cloud-based infrastructure, including WebDAV-backed public cloud storage in some campaigns.
A core function of VBCloud is theft and exfiltration of victim data. Observed behavior includes searching for and stealing documents and archives of intelligence interest, including common office and text formats, recent files, and Telegram-related artifacts. Stolen data has been packaged into encrypted archives and exfiltrated through attacker-controlled cloud channels. VBCloud has also been described as downloading and executing additional malicious scripts, including file-grabber functionality, making it both a persistent backdoor and a data-theft platform within Cloud Atlas operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Victims get infected via phishing emails containing a malicious document that exploits a vulnerability in the formula editor (CVE-2018-0802) to download and execute malware code.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Мы также фиксировали инциденты, в которых на зараженные хосты устанавливались дополнительные собственные разработки группы, такие как VBCloud и PowerCloud.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
In the case of VBCloud, the script changes the extension of the unpacked file from TXT to VBS and creates a scheduler task to run VBCloud.
PowerShower downloads additional PowerShell scripts from the C2 and executes these.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Additional proprietary Cloud Atlas backdoor/tool observed in some incidents on infected hosts.
A backdoor deployed by Cloud Atlas after phishing-based initial access to maintain persistent access inside compromised networks.
Backdoor deployed by Fixed.ps1. Its launcher decrypts and executes the encrypted payload in memory, connects to a command server, receives additional scripts or executes built-in commands, and steals/exfiltrates files such as DOC, PDF, and XLS.
Custom malware family used by Cloud Atlas and distributed via phishing Word documents (remote template technique noted in the described chain).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.