Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code

The Cloud Atlas advanced persistent threat group has maintained its campaign targeting organizations in Eastern Europe and Central Asia during the first half of 2025, utilizing outdated Microsoft Office vulnerabilities to deploy backdoor implants.

The Cloud Atlas advanced persistent threat group has maintained its campaign targeting organizations in Eastern Europe and Central Asia during the first half of 2025, utilizing outdated Microsoft Office vulnerabilities to deploy backdoor implants.

This campaign illustrates a concerted effort to gain persistent access and extract sensitive data from high-value targets.

Active since 2014, Cloud Atlas has consistently refined its attack methods and expanded its toolkit. The group's infrastructure typically initiates with phishing emails containing malicious documents exploiting CVE-2018-0802, a vulnerability in the Microsoft Office Equation Editor.

Upon opening a compromised file, a series of malware components are downloaded and executed in a structured infection chain.

Securelist analysts identified that the infection begins when users open a Word document with a malicious template from attacker-controlled servers.

This campaign illustrates a concerted effort to gain persistent access and extract sensitive data from high-value targets.
Robert Langley · Thehackingpost

The document loads an RTF file with an exploit for the Equation Editor, which downloads and executes an HTML Application file. This initial payload extracts multiple VBS files on the target system, forming the base for additional backdoors, including VBShower, PowerShower, VBCloud, and CloudAtlas.

The threat group demonstrates sophistication in evasion and persistence techniques. The VBShower backdoor, operating as the primary launcher, executes downloaded VB scripts regardless of file size, enabling flexible payload deployment.

Infection Mechanism and Persistence Tactics

The VBCloud implant is a key component in Cloud Atlas's operations. Working with a launcher script, VBCloud maintains encrypted communication with command servers through cloud-based infrastructure. The launcher reads encrypted payload data, applies RC4 decryption, and executes the decrypted content. This implementation uses the PRGA algorithm within RC4, indicating operational maturity.

The persistence mechanism incorporates Windows Task Scheduler to ensure access across system reboots. The malware creates scheduled tasks mimicking legitimate services, executing VBS scripts regularly to remain operational after restarts.

Advertisement

File operations involve using the %Public% and %LOCALAPPDATA% directories, establishing hidden infrastructure through renamed files and encrypted payloads.

The CloudAtlas backdoor communicates via WebDAV protocols to cloud services, establishing encrypted command channels that blend with legitimate traffic. It creates directories using HTTP MKCOL and retrieves payloads through PROPFIND requests. Operators can deploy plugin modules for functions like file grabbing and system information collection.

The campaign targets sectors such as telecommunications, construction, government, and industrial facilities in Russia and Belarus, posing significant risks with its multi-staged infection process and post-exploitation capabilities.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories