Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

Cloud Atlas APT group targeted government organizations and commercial companies in Russia and Belarus during late 2025 and early 2026, employing phishing campaigns with malicious ZIP archives containing LNK shortcuts. The attackers deployed multiple backdoors including VBCloud for file theft and PowerShower for network reconnaissance. New tools identified include PowerCloud, which exfiltrates data to Google Sheets, and browser checker utilities. The group established persistence through reverse SSH tunnels, patched OpenSSH binaries, ReverseSocks, and Tor networking. Initial infection vectors included malicious shortcuts executing PowerShell scripts and exploiting CVE-2018-0802 in Microsoft Office. The attackers performed credential theft, RDP manipulation via termsrv.dll patching, and lateral movement across networks while maintaining multiple backup control channels.

Pulse ID: 6a105530af26afbd3752ab81
Pulse Link: https://otx.alienvault.com/pulse/6a105530af26afbd3752ab81
Pulse Author: AlienVault
Created: 2026-05-22 13:08:00

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Belarus #Browser #Cloud #CloudAtlas #CyberSecurity #Google #Government #InfoSec #LNK #Microsoft #MicrosoftOffice #OTX #Office #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #Russia #SSH #ZIP #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

C# Corner software developer Deepak Tewatia does a thorough review of available .NET libraries for automating Microsoft Word (and other apps in the Office suite) writes, reads, and conversions from within Windows, MacOS, and Linux. Both commercial and FOSS alternatives are explored, including applicable license types.

"C# Word Library: Comparing 7 Options for .NET Developers in 2026"

https://www.c-sharpcorner.com/article/c-sharp-word-library-comparing-7-options-for-net-developers-in-2026/

#programming #dotnet #csharp #microsoftoffice #windows #macos #linux

https://winbuzzer.com/2026/05/24/microsoft-confirms-classic-outlook-image-rendering-bug-xcxwbn/

Microsoft has acknowledged a classic Outlook bug that drops embedded images from emails, newsletters, and image-based signatures whenever the Wrap Text with Top and Bottom formatting option is used.

#MicrosoftOutlook #Microsoft365 #MicrosoftOffice #Microsoft #Email

SUGGESTED READS FOR MAY 24, 2026

GREJSIMOJS: il design svedese che ha smesso di fare l'adulto – [GREJSIMOJS: Swedish design that stopped acting like an adult], please use a translation service to read Come bloccare l’uso dei nostri dati per allenare l’Intelligenza Artificiale – [Your data is not a buffet: how to deny "consent" to AI] A practical guide to reclaiming your privacy among ChatGPT, social media, and creative programs, please use a translation service to read Trapped in MS Office – a great piece by iA […]

https://nicolalosito.it/2026/05/24/suggested-reads-for-may-24-2026/

🚨 NEWS: Indagini Antitrust e Lotta alla Pirateria: Il 2026 Segna una Nuova Era di Regolamentazione Tech

Ecco i punti chiave in breve:
💡 Il panorama tecnologico globale sta attraversando una fase di profonda trasformazione normativa. Due eventi recenti, seppur diversi per natura, evidenziano una tendenza inequivocab...

🚀 LINK: https://meteoraweb.com/news/indagini-antitrust-e-lotta-alla-pirateria-il-2026-segna-una-nuova-era-di-regolamentazione-tech

#copilot #antitrust #regolamentazioneDigitale #microsoftOffice #pirateriaStreaming

LibreOffice accuse Microsoft d'avoir fait disparaître son seul format Word conforme à la norme ISO

En 2008, Microsoft promettait à l'ISO que la version standardisée d'OOXML remplacerait la version provisoire. Dix-huit ans plus tard, c'est la version provisoire qui a gagné, et la version standardisée qui a disparu.

clubic.com

Cloud Atlas Expands Arsenal with New Tools, Payloads

Cloud Atlas is beefing up its toolkit with fresh tools and payloads, including a blast from the past - the notorious CVE-2018-0802 Microsoft Office Equation Editor vulnerability. The group is also reviving its use of ZIP archives with malicious LNK shortcuts that trigger PowerShell scripts, keeping security experts on high alert.

https://osintsights.com/cloud-atlas-expands-arsenal-with-new-tools-payloads?utm_source=mastodon&utm_medium=social

#CloudAtlas #Cve20180802 #MicrosoftOffice #Powershell #LnkShortcut

Cloud Atlas Expands Arsenal with New Tools, Payloads

Discover how Cloud Atlas expands its arsenal with new tools and payloads, exploiting old vulnerabilities and phishing tactics, learn more about their latest campaigns now.

OSINTSights

Montag: Neue Digitalsteuer für Big-Tech, Meta-Smartglasses mit mehr Funktionen

US-Steuer für Cloud-Software + Ray-Ban Display erkennt Handschrift + Finanzratschläge von ChatGPT + SaaSpocalypse für Tech-Riesen + Alternativen zu MS-Office

https://www.heise.de/news/Montag-Neue-Digitalsteuer-fuer-Big-Tech-Meta-Smartglasses-mit-mehr-Funktionen-11296641.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#ChatGPT #CloudComputing #CloudDienste #DigitaleSouveränität #hoDaily #Journal #KünstlicheIntelligenz #MetaPlatforms #MicrosoftOffice #OpenAI #Steuerrecht #Wearables #news

Montag: Neue Digitalsteuer für Big-Tech, Meta-Smartglasses mit mehr Funktionen

US-Steuer für Cloud-Software + Ray-Ban Display erkennt Handschrift + Finanzratschläge von ChatGPT + SaaSpocalypse für Tech-Riesen + Alternativen zu MS-Office

heise online
Ich will kein Office Paket, ich will ein Freizeit Paket. #LibreOffice #OnlyOffice #MicrosoftOffice #CollaboraOffice

Video: Statt Microsoft — Diese vier Office-Pakete solltet ihr kennen

Wer nach datenschutzfreundlichem und günstigerem Ersatz für Microsoft Office sucht, findet mindestens vier gute Alternativen. Wir stellen sie im Video vor.

https://www.heise.de/news/Video-Statt-Microsoft-Diese-vier-Office-Pakete-solltet-ihr-kennen-11269405.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#DigitaleSouveränität #IT #MicrosoftOffice #Video #news

Video: Statt Microsoft — Diese vier Office-Pakete solltet ihr kennen

Wer nach datenschutzfreundlichem und günstigerem Ersatz für Microsoft Office sucht, findet mindestens vier gute Alternativen. Wir stellen sie im Video vor.

heise online