Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cloud Atlas Exploits Office Vulnerabilities to Execute Malicious Code

## Cybersecurity: Cloud Atlas Threat Group Analysis

Cybersecurity: Cloud Atlas Threat Group Analysis

The Cloud Atlas threat group, active since 2014, poses significant risks to organizations in Eastern Europe and Central Asia through advanced attacks exploiting legacy Microsoft Office vulnerabilities.

Security researchers have documented the group's expanded toolkit and evolving infection chains deployed in the first half of 2025, revealing new implants and attack methods.

Cloud Atlas initiates attacks using phishing emails containing malicious Word documents. Upon opening, these documents exploit CVE-2018-0802, a vulnerability in the Microsoft Office Equation Editor process.

This seven-year-old flaw remains effective, underscoring the risks of unpatched legacy systems in enterprise environments.

The initial HTA file acts as a staging mechanism, creating multiple VBS files that deploy the VBShower backdoor, the group's primary initial access tool.

VBShower then deploys three additional backdoors: PowerShower, VBCloud, and CloudAtlas, providing flexibility and redundancy in maintaining persistent access.

Cloud Atlas initiates attacks using phishing emails containing malicious Word documents.
Eleanor Tate · Thehackingpost

The infection flow mirrors past attack patterns with improvements in file naming and execution methods. VBShower's updates remove previous payload size restrictions, enhancing its execution capabilities.

New components enhance surveillance capabilities. Payload variants collect detailed process information and systematically check cloud services for viable command-and-control channels.

FileGrabber components scan systems for recently modified documents while adhering to file size restrictions to prioritize data collection without detection.

CloudAtlas: The Advanced Persistent Backdoor

The CloudAtlas backdoor leverages DLL hijacking attacks and uses the VLC media player as an unwitting loader for malicious libraries. Communication uses WebDAV protocol, with encrypted beacons transmitting system data.

Advertisement

Technical indicators, YARA rules, and threat intelligence are available through the Kaspersky Intelligence Reporting Service for enterprise customers.

CloudAtlas plugins offer targeted functionality, including document theft, system information collection, credential extraction from browsers, and arbitrary command execution.

Active campaigns in early 2025 targeted organizations in Russia and Belarus, affecting sectors such as telecommunications, construction, government agencies, and manufacturing.

The persistence of CVE-2018-0802 highlights the importance of patching legacy systems and hardening applications. Organizations should implement Office macro restrictions, email filtering, and monitoring for VBS script execution.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories