Cloud Atlas Resurfaces in 2025 With a Sophisticated Multi-Backdoor Campaign Targeting Eastern Europe and Central Asia

Listen to this Post

Featured Image

Introduction: A Quiet but Persistent Cyber Espionage Operation

For more than a decade, the Cloud Atlas threat group has operated with discipline, patience, and technical depth, quietly maintaining access to strategic networks across Eastern Europe and Central Asia. Active since at least 2014, the group has never relied on loud, destructive attacks. Instead, it has focused on stealth, persistence, and long-term intelligence collection.

Throughout 2025, Cloud Atlas has continued refining its tradecraft, leaning heavily on legacy Microsoft Office vulnerabilities and layered malware architectures. By combining old but reliable exploits with modern operational security techniques, the group demonstrates how advanced threat actors can remain effective without relying on zero-day vulnerabilities or noisy ransomware campaigns.

This article examines Cloud Atlas’s current infection chain, its evolving backdoor ecosystem, and why this campaign remains relevant for defenders today.

Summary of the Original

A Long-Running Threat Actor With Regional Focus

Cloud Atlas is a cyber-espionage group that has been active for over ten years, primarily targeting organizations in Eastern Europe and Central Asia. Its operations have remained consistent in purpose but have evolved technically, with 2025 activity showing notable refinements.

Phishing as the Primary Entry Vector

The group initiates attacks through phishing emails that contain malicious DOC or DOCX attachments. These documents appear legitimate and are crafted to entice victims into opening them, triggering the next stage of the infection chain.

Abuse of Microsoft Office Equation Editor

Once opened, the malicious document downloads a remote RTF template that exploits CVE-2018-0802, a known vulnerability in the Microsoft Office Equation Editor. Despite its age, this vulnerability remains effective in environments running unpatched or legacy Office installations.

Execution of HTA Files for Initial Access

The exploit allows the execution of HTML Application (HTA) files, which are used to establish an initial foothold on the victim system. This stage is critical, as it prepares the environment for further payload deployment.

Carefully Controlled Attack Infrastructure

Cloud Atlas hosts malicious templates and HTA files on attacker-controlled servers with time-based and IP-restricted access. Once a system is successfully infected, the download links become inaccessible, hindering forensic analysis and reducing exposure.

Deployment of the VBShower Backdoor

After exploitation, the HTA file installs VBShower through multiple VBS scripts. VBShower acts as the central controller for subsequent stages of the attack.

Orchestration of Multiple Backdoors

VBShower deploys three additional backdoors: PowerShower, VBCloud, and CloudAtlas. Each implant provides overlapping capabilities while also offering specialized functions to ensure redundancy.

Memory-Only Payload Execution

The malware has evolved to execute downloaded payloads directly in memory, regardless of file size. This approach minimizes disk artifacts and complicates detection and post-incident investigations.

PowerShower’s Stealthy Persistence

PowerShower is a PowerShell-based backdoor installed via scheduled tasks that masquerade as Adobe update services. It uses registry manipulation to hide execution windows and relies on Base64-encoded scripts for command-and-control communications.

VBCloud’s Encrypted Architecture

VBCloud employs a launcher-and-payload model, using RC4 encryption to decrypt and execute its core functionality. It communicates independently with command-and-control servers and can download additional malicious components.

Securelist as the Most Advanced Implant

The Securelist backdoor is delivered through DLL hijacking of legitimate VLC Media Player installations. It uses AES-256-CBC encryption and leverages WebDAV-enabled cloud services to retrieve encrypted plugins.

Modular Plugin Capabilities

Observed plugins include FileGrabber for document theft, PasswordStealer for harvesting Chromium-based browser credentials, InfoCollector for reconnaissance, and Common modules for remote code execution and registry operations.

Ongoing Targeting Across Multiple Sectors

Kaspersky telemetry confirms continued activity throughout 2025, with victims in Russia and Belarus across telecommunications, construction, government, and industrial sectors, highlighting Cloud Atlas’s sustained operational capability.

What Undercode Say:

Legacy Exploits Still Win in the Real World

Cloud Atlas proves that attackers do not need cutting-edge zero-days to succeed. CVE-2018-0802 is years old, yet it remains effective because many organizations still rely on outdated Microsoft Office environments. Attackers understand operational reality better than defenders sometimes do.

Operational Security as a Force Multiplier

The use of time-limited and IP-restricted payload hosting shows a deep understanding of defensive workflows. By removing access after infection, Cloud Atlas significantly reduces opportunities for reverse engineering and threat intelligence collection.

Redundancy as a Survival Strategy

Deploying multiple backdoors with overlapping capabilities is not wasteful—it is strategic. If one implant is detected or neutralized, others remain active, ensuring continued access. This design reflects mature, long-term espionage thinking rather than smash-and-grab tactics.

Memory-Resident Malware Is Now the Baseline

Executing payloads directly in memory is no longer an advanced trick; it is becoming standard practice among well-funded threat groups. Cloud Atlas’s ability to run large payloads in memory demonstrates confidence in both tooling and target environment stability.

Living Off the Land Still Matters

PowerShower’s abuse of scheduled tasks, registry settings, and PowerShell highlights how legitimate system features remain powerful tools for attackers. These techniques blend malicious activity into normal administrative noise.

Encryption Everywhere, Visibility Nowhere

From RC4 in VBCloud to AES-256-CBC in Securelist, encryption is used consistently to protect configurations, payloads, and communications. This layered encryption strategy significantly raises the bar for defenders relying on network inspection alone.

Cloud Services as Covert Channels

The use of WebDAV-enabled cloud services for plugin delivery shows how attackers increasingly hide malicious traffic inside trusted platforms. Blocking such services outright is often impractical for enterprises.

DLL Hijacking Remains Underrated

Securelist’s delivery via VLC Media Player DLL hijacking underscores how trusted applications can be turned into unwitting loaders. This technique exploits both user trust and software distribution habits.

Intelligence Collection Over Disruption

Unlike ransomware-driven campaigns, Cloud Atlas prioritizes silent data collection. Document theft, credential harvesting, and system profiling all point toward strategic intelligence goals rather than financial gain.

Sector Targeting Reflects Geopolitical Interest

The focus on telecommunications, government, and industrial sectors suggests nation-state alignment or sponsorship. These are not random victims; they are carefully selected for long-term informational value.

Detection Requires Behavioral, Not Signature-Based Defense

Traditional antivirus signatures struggle against this kind of layered, encrypted, memory-resident malware. Behavioral monitoring, anomaly detection, and strong email security remain critical.

Patch Management Is Still the First Line of Defense

Despite the sophistication of later stages, the initial entry relies on a patched vulnerability. This reinforces a simple truth: basic hygiene can still stop advanced threats.

Cloud Atlas Is Not Loud, but It Is Dangerous

The group’s quiet persistence makes it more dangerous than flashier actors. Organizations may remain compromised for months or years without realizing it.

2025 Shows Evolution, Not Reinvention

Cloud Atlas has not radically changed its playbook; it has refined it. This incremental improvement is often more effective than dramatic innovation.

A Case Study in Modern Espionage Malware

Overall, this campaign serves as a textbook example of contemporary cyber-espionage: stealthy entry, layered persistence, encrypted communications, and long-term access.

Fact Checker Results

Technical Consistency

The described infection chain and backdoor components align with known Cloud Atlas tooling. ✅

Vulnerability Usage

CVE-2018-0802 remains a documented and historically abused Microsoft Office vulnerability. ✅

Targeting Claims

Reported victim sectors and regions are consistent with previously observed Cloud Atlas activity. ✅

Prediction

Continued Abuse of Legacy Software

Cloud Atlas is likely to keep exploiting outdated Office installations as long as they remain common. 🔮

Deeper Cloud Service Integration

Future versions of the malware may further embed command-and-control traffic into legitimate cloud platforms. 🔮

Expansion Without Public Noise

Rather than shifting to ransomware or overt disruption, Cloud Atlas will likely expand quietly, maintaining its low-profile espionage model. 🔮

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon