Inception_Framework__2022__Checkpoint_Cloud-Atlas-targets-Russia-Belarus-amid-Ukraine_12-09-2022.pdf
ID: ed8db29d-9b46-4a60-907d-3c3b0a54f798
STIX ID: report--ed8db29d-9b46-4a60-907d-3c3b0a54f798
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2023-03-13
Last Modified Date: 2023-03-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cloud Atlas (aka Inception) is an active cyber-espionage group focused recently on Russia, Belarus and contested areas around Ukraine; the report details their spear-phishing initial access (weaponized Office remote templates exploiting CVE-2017-11882/CVE-2018-0802), the PowerShower PowerShell backdoor, a .NET DLL proxy component (rtcpsvc/rtcpProxy) used to relay and XOR-encrypt traffic, and a persistent modular DLL-based espionage framework using cloud WebDAV (OpenDrive) for C2. The analysis includes victimology, post-exploitation behaviors (NTDS extraction, RDP lateral movement, use of legitimate admin tools and remote access utilities), example code fragments, and a list of hashes, domains and other IOCs.
