Cloud Atlas Exploits Office Vulnerabilities to Execute Malicious Code
## Cybersecurity: Cloud Atlas Threat Group Analysis
Cybersecurity: Cloud Atlas Threat Group Analysis
The Cloud Atlas threat group, active since 2014, poses significant risks to organizations in Eastern Europe and Central Asia through advanced attacks exploiting legacy Microsoft Office vulnerabilities.
Security researchers have documented the group's expanded toolkit and evolving infection chains deployed in the first half of 2025, revealing new implants and attack methods.
Cloud Atlas initiates attacks using phishing emails containing malicious Word documents. Upon opening, these documents exploit CVE-2018-0802, a vulnerability in the Microsoft Office Equation Editor process.
This seven-year-old flaw remains effective, underscoring the risks of unpatched legacy systems in enterprise environments.
The initial HTA file acts as a staging mechanism, creating multiple VBS files that deploy the VBShower backdoor, the group's primary initial access tool.
VBShower then deploys three additional backdoors: PowerShower, VBCloud, and CloudAtlas, providing flexibility and redundancy in maintaining persistent access.
Cloud Atlas initiates attacks using phishing emails containing malicious Word documents.
The infection flow mirrors past attack patterns with improvements in file naming and execution methods. VBShower's updates remove previous payload size restrictions, enhancing its execution capabilities.
New components enhance surveillance capabilities. Payload variants collect detailed process information and systematically check cloud services for viable command-and-control channels.
FileGrabber components scan systems for recently modified documents while adhering to file size restrictions to prioritize data collection without detection.
CloudAtlas: The Advanced Persistent Backdoor
The CloudAtlas backdoor leverages DLL hijacking attacks and uses the VLC media player as an unwitting loader for malicious libraries. Communication uses WebDAV protocol, with encrypted beacons transmitting system data.
Technical indicators, YARA rules, and threat intelligence are available through the Kaspersky Intelligence Reporting Service for enterprise customers.
CloudAtlas plugins offer targeted functionality, including document theft, system information collection, credential extraction from browsers, and arbitrary command execution.
Active campaigns in early 2025 targeted organizations in Russia and Belarus, affecting sectors such as telecommunications, construction, government agencies, and manufacturing.
The persistence of CVE-2018-0802 highlights the importance of patching legacy systems and hardening applications. Organizations should implement Office macro restrictions, email filtering, and monitoring for VBS script execution.
Based on reporting by GBHackers.
