Cloud Atlas: RedOctober APT is back in style - Securelist
ID: 8ca2f8c3-7d59-448b-9cbe-05458aa0187b
STIX ID: report--8ca2f8c3-7d59-448b-9cbe-05458aa0187b
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2014-12-10
Last Modified Date: 2014-12-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Cloud Atlas** is a targeted cyber-espionage campaign—likely a revival of the RedOctober APT—that uses CVE-2012-0158 Office exploits to deploy polymorphic VBScript loaders and encrypted DLL payloads which communicate over HTTPS/WebDAV using abused cloud storage accounts (cloudme.com); the report provides technical analysis, configuration and C2 artifacts, victim geography (primarily Russia and nearby states), LZMA/AES usage, build-tool similarities to RedOctober, and a list of IoCs and AV detections.
