Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cloud Atlas used malicious Office documents to exploit CVE-2018-0802 and deliver CloudAtlasGo.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cloud Atlas used malicious Office documents to exploit CVE-2018-0802 and deliver CloudAtlasGo.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
All 81 vulnerabilities below were actively exploited or operationally weaponized in July 2026... 57 of the 85 vulnerabilities enabled remote code execution (RCE)... JADEPUFFER and Cl0p targeted exposed AI and product-lifecycle platforms for encryption, data theft, and extortion.
netscan Информация о сетевых интерфейсах, IP-адресах, масках подсетей.
netscan ... Перебирает IP-адреса в диапазоне обнаруженных подсетей и пробует установить подключение к портам 22, 80, 135, 139, 443, 445, 3389, 5985 для проверки их доступности.
hostname Информация о текущем имени хоста. systeminfo, info Получение базовой информации о системе...
Команда Описание ... ls, dir Выполняет листинг директории ... find, search Поиск файла по заданным критериям.
В качестве основного канала связи он использует WebRTC, а для отправки сигналов об установке соединения — облачные сервисы.
...для передачи сигналов SDP используются облачные сервисы, одним из которых является Trello... бэкдор использует его API... Помимо API Trello, бэкдор может устанавливать соединение WebRTC, используя такие протоколы, как WebDAV или SFTP.
...Все сообщения, не попадающие под описанные выше категории, интерпретируются как запросы на установление соединений между C2 и удаленными системами с использованием зараженной системы в качестве прокси.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware payload delivered via abuse of Microsoft Equation Editor.
Malware delivered via malicious Office documents after exploitation of CVE-2018-0802 in an espionage-focused campaign.
Golang backdoor used by Cloud Atlas that communicates via WebRTC and uses cloud services such as Trello, as well as WebDAV or SFTP, for SDP signaling. It supports file upload/download, arbitrary command execution, proxying, port forwarding, DNS resolution through the victim, and basic anti-analysis checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.