State-backed threat actor Cloud Atlas (also known as Inception) launched a cyberespionage campaign targeting Russian agricultural organizations by leveraging phishing emails disguised as official communications for an upcoming industry forum. The attackers distributed malicious files exploiting the eight-year-old Microsoft Office vulnerability CVE-2017-11882, enabling them to execute arbitrary code, compromise systems, install unauthorized software, manipulate data, and create new user accounts. This campaign was uncovered by Russian cybersecurity firm F6, which noted that the phishing lures were specifically crafted around the industry event to increase their effectiveness.
Researchers observed that Cloud Atlas has intensified its operations against Russian and Belarusian targets in 2025, with indications that a defense enterprise was also among the recent victims. The group continues to rely on long-known vulnerabilities and established infection chains, suggesting that their attacks remain successful due to unpatched systems and human error. F6 highlighted that Cloud Atlas is refining its tools and experimenting with new payloads, but the persistent use of old exploits like CVE-2017-11882 underscores the ongoing risk posed by poor cybersecurity hygiene in targeted organizations.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Ahead of an upcoming industry forum in Moscow, Cloud Atlas targeted Russia's agricultural sector with phishing emails themed around the event and exploited CVE-2017-11882 to deliver malicious payloads.
The reported campaign was described as the second recent Cloud Atlas attack against Russian agro-industrial companies, indicating at least one prior 2025 operation against the sector.
Researchers observed heightened Cloud Atlas activity during 2025, including campaigns targeting agricultural and defense enterprises in Russia and Belarus.
Researchers describe Cloud Atlas, also known as Inception, as an espionage group that has been active since at least 2014, using phishing, custom malware loaders, and encrypted communications for data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.