Researchers attributed a sustained cyber-espionage campaign against government, diplomatic, and commercial organizations in Russia and Belarus to the Cloud Atlas APT group, linking activity seen through 2025 and into 2026 to phishing and stealthy remote-access operations. Initial access relied on phishing emails carrying ZIP archives with malicious .lnk files that launched external PowerShell scripts, while some intrusions also used older weaponized Office documents exploiting CVE-2018-0802.
Once inside victim networks, Cloud Atlas deployed an expanded toolset that included VBCloud for file theft, PowerShower for reconnaissance, lateral movement, Kerberoasting, credential theft, and UAC bypass, plus a newly identified PowerCloud utility. The operators also used reverse SSH tunnels, RevSocks, Tor, and public tools such as OpenSSH to maintain resilient backup command-and-control channels, and patched termsrv.dll to allow multiple concurrent RDP sessions without interrupting legitimate users. Researchers said the attribution was made with high confidence based on the group’s tooling, techniques, victim profile, and geographic focus, despite some limited infrastructure overlap with Head Mare.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The activity continued into 2026, with tooling used for file theft, reconnaissance, lateral movement, Kerberoasting, credential theft, UAC bypass, and patching termsrv.dll to enable multiple concurrent RDP sessions without disrupting legitimate users. Telemetry indicated primary targeting of government and diplomatic entities in Russia and Belarus.
During the 2025-2026 campaign, the attackers used phishing emails with ZIP archives containing malicious LNK files that launched external PowerShell scripts, alongside older malicious Office documents exploiting CVE-2018-0802. These infection chains deployed tools including VBCloud, PowerShower, reverse SSH tunnels, Tor-based access, and the newly identified PowerCloud utility.
Researchers observed sustained SSH tunneling activity during 2025 targeting government and commercial organizations in Russia and Belarus. The activity used public tools such as OpenSSH, RevSocks, and Tor to maintain resilient command-and-control and backup access channels.
A November 2024 analysis described a phishing archive masquerading as a 1C-related file that executed a fake 1C:Enterprise window while extracting and decrypting a multi-stage payload. The malware installed SSH-based persistence, created a local user named 'config,' deployed a custom Go2Tunnel reverse-tunneling utility, and exposed associated hashes and IP indicators.
In its report, Securelist attributed part of the sustained SSH tunneling activity to the Cloud Atlas APT group with high confidence based on tooling, techniques, victimology, and geography. The researchers noted some infrastructure and directory overlaps with Head Mare activity but concluded the TTPs were distinct.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 114 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securelist.ru
Open sourcebi.zone
Open sourcert-solar.ru
Open sourcet.me
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.