logo

Cloud Atlas: RedOctober APT is back in style - Securelist

ID: 8ca2f8c3-7d59-448b-9cbe-05458aa0187b

STIX ID: report--8ca2f8c3-7d59-448b-9cbe-05458aa0187b

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2014-12-10

Last Modified Date: 2014-12-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Cloud Atlas** is a targeted cyber-espionage campaign—likely a revival of the RedOctober APT—that uses CVE-2012-0158 Office exploits to deploy polymorphic VBScript loaders and encrypted DLL payloads which communicate over HTTPS/WebDAV using abused cloud storage accounts (cloudme.com); the report provides technical analysis, configuration and C2 artifacts, victim geography (primarily Russia and nearby states), LZMA/AES usage, build-tool similarities to RedOctober, and a list of IoCs and AV detections.