Cloud Atlas Hacker Group Exploiting Office Vulnerabilities to Execute Malicious Code
The Cloud Atlas advanced persistent threat group has maintained its campaign targeting organizations in Eastern Europe and Central Asia during the first half of 2025, utilizing outdated Microsoft Office vulnerabilities to deploy backdoor implants.
The Cloud Atlas advanced persistent threat group has maintained its campaign targeting organizations in Eastern Europe and Central Asia during the first half of 2025, utilizing outdated Microsoft Office vulnerabilities to deploy backdoor implants.
This campaign illustrates a concerted effort to gain persistent access and extract sensitive data from high-value targets.
Active since 2014, Cloud Atlas has consistently refined its attack methods and expanded its toolkit. The group's infrastructure typically initiates with phishing emails containing malicious documents exploiting CVE-2018-0802, a vulnerability in the Microsoft Office Equation Editor.
Upon opening a compromised file, a series of malware components are downloaded and executed in a structured infection chain.
Securelist analysts identified that the infection begins when users open a Word document with a malicious template from attacker-controlled servers.
This campaign illustrates a concerted effort to gain persistent access and extract sensitive data from high-value targets.
The document loads an RTF file with an exploit for the Equation Editor, which downloads and executes an HTML Application file. This initial payload extracts multiple VBS files on the target system, forming the base for additional backdoors, including VBShower, PowerShower, VBCloud, and CloudAtlas.
The threat group demonstrates sophistication in evasion and persistence techniques. The VBShower backdoor, operating as the primary launcher, executes downloaded VB scripts regardless of file size, enabling flexible payload deployment.
Infection Mechanism and Persistence Tactics
The VBCloud implant is a key component in Cloud Atlas's operations. Working with a launcher script, VBCloud maintains encrypted communication with command servers through cloud-based infrastructure. The launcher reads encrypted payload data, applies RC4 decryption, and executes the decrypted content. This implementation uses the PRGA algorithm within RC4, indicating operational maturity.
The persistence mechanism incorporates Windows Task Scheduler to ensure access across system reboots. The malware creates scheduled tasks mimicking legitimate services, executing VBS scripts regularly to remain operational after restarts.
File operations involve using the %Public% and %LOCALAPPDATA% directories, establishing hidden infrastructure through renamed files and encrypted payloads.
The CloudAtlas backdoor communicates via WebDAV protocols to cloud services, establishing encrypted command channels that blend with legitimate traffic. It creates directories using HTTP MKCOL and retrieves payloads through PROPFIND requests. Operators can deploy plugin modules for functions like file grabbing and system information collection.
The campaign targets sectors such as telecommunications, construction, government, and industrial facilities in Russia and Belarus, posing significant risks with its multi-staged infection process and post-exploitation capabilities.
Based on reporting by Cyber Security News.
