Inception is a Windows malware framework associated with the Cloud Atlas espionage actor. Public reporting linked the framework to targeted intrusions against government and diplomatic entities, particularly in Russia and neighboring regions. It is designed for long-term compromise and intelligence collection, combining persistence, host reconnaissance, credential theft, and covert command-and-control communications.
The framework has been observed establishing persistence through Windows Registry Run key modification. It includes reconnaissance functionality to enumerate active processes and loaded modules on infected systems, supporting operator awareness and follow-on tasking. Inception also contains a browser-focused credential theft component that steals saved passwords and active session data from multiple browsers, including mainstream Chromium- and Gecko-based products as well as regional browsers.
For communications, Inception has used web protocols including HTTP, HTTPS, and WebDAV, and encrypted network traffic with AES to protect command-and-control and exfiltration activity. Infection has been associated with social-engineering lures that entice victims to open malicious files, after which the malware can perform machine reconnaissance and execute additional malicious functionality. Overall, Inception is best characterized as an espionage-oriented modular platform used for stealthy collection from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Once inside, the handler itself became the training gadget, armed with Inception (CVE-2023-20569) to fill the return stack buffer with an attacker-chosen target. Inception is the 2023 AMD flaw saferet exists to stop.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December 2014, Blue Coat exposed a newly discovered malware framework dubbed ‘Inception’ [4, 5], which was later attributed to a new actor named ‘Cloud Atlas’ [6].
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
"...used tasklist to enumerate processes..."; "...used the ps command to list processes..."; "...calling CreateToolhelp32Snapshot... to enumerate the running processes..."
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A speculative execution / branch prediction attack technique against AMD processors that can poison return prediction state; here it is used as a component of the interrupt-injection attack chain.
Backdoor malware that persists by modifying a user Run registry value.
Backdoor with recon module that enumerates processes and loaded modules.
Malware that uses HTTP/HTTPS/WebDAV in network communications (including C2).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.