Recent Cloud Atlas activity
ID: 2885bf04-04b2-4e26-ad39-92b4c0649bd4
STIX ID: report--2885bf04-04b2-4e26-ad39-92b4c0649bd4
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2019-09-16
Last Modified Date: 2019-09-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky researchers describe recent Cloud Atlas activity: targeted spear-phishing using malicious remote Office templates and a polymorphic HTA/VBS chain that deploys VBShower (validator) and PowerShower (PowerShell backdoor) to load document- and credential-stealing modules and a second-stage modular backdoor. The report includes infection chain diagrams, details of commands and modules, persistence and anti-forensics behaviors, exploited CVEs (CVE-2017-11882, CVE-2018-0802), and IoCs (attacker emails, registry Run key pattern, file paths and C2 IPs).
