CloudAtlas is a Windows backdoor associated with the Cloud Atlas APT group, which has targeted organizations in Eastern Europe and Central Asia, including entities in Russia and Belarus across sectors such as government, telecommunications, construction, and industry. The malware is part of a broader multi-stage intrusion chain that commonly begins with phishing emails carrying malicious Microsoft Office documents exploiting CVE-2018-0802. Subsequent stages use HTA, VBS, and PowerShell components, including VBShower and PowerShower, to install additional implants.
CloudAtlas is deployed through DLL sideloading using a legitimate VLC application as a loader for an encrypted payload. It communicates with command-and-control infrastructure over WebDAV and abuses public cloud services for command-and-control operations, a design choice that complicates detection and disruption. The backdoor is modular and can retrieve executable DLL plugins that extend functionality.
Documented plugin capabilities include file theft, arbitrary command execution, browser password theft from Chromium-based browsers, and host information collection. Related reporting also describes the Cloud Atlas toolset as supporting reconnaissance, credential theft, and exfiltration through overlapping implants such as VBCloud and PowerShower. CloudAtlas uses encrypted payloads and configuration data and is part of a long-running, evolving espionage-oriented malware ecosystem maintained by the Cloud Atlas threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ранее мы уже встречали подобный способ C2-коммуникации у бэкдора группы под названием CloudAtlas, который использовал протокол WebDAV и общедоступные облачные сервисы в качестве C2.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously observed Cloud Atlas backdoor that used WebDAV and public cloud services for C2; mentioned as a comparison to CloudAtlasGo.
CloudAtlas is a backdoor used by the Cloud Atlas threat actor, capable of gathering files, running commands, stealing browser passwords, and capturing system information.
CloudAtlas is a sophisticated backdoor used by the Cloud Atlas APT group. It is delivered via DLL hijacking, uses cloud services for C2, and supports plugins for file exfiltration, credential theft, system information collection, and remote command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.