INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cloud Atlas Exploitation Tool and Payload

| 2026-05-22 09:12 CRITICAL HIGH
Executive Summary AI-generated
The incident involves a sophisticated cyber attack that has been ongoing since 2025, with the malicious activities persisting into 2026. The attackers have targeted government organizations and commercial companies in Russia and Belarus, exploiting vulnerabilities to gain access and establish persistent backdoors. A PhantomHeart backdoor, attributed to Head Mare, was used to create an SSH tunnel, while a deobfuscated script identified victims as locations of interest. Technical details reveal the use of phishing, network reconnaissance, lateral movement, and malicious documents to deliver malware payloads. The attackers have also employed anti-forensic cleanup techniques to erase evidence of their presence. This incident highlights the evolving nature of cyber threats and the need for robust security measures to counter such sophisticated attacks.
Technical Mitigations AI-generated
• Implement a robust anti-malware solution with advanced signature-based detection and behavior-based detection to detect and prevent Cloud Atlas activity. • Conduct regular security audits and penetration testing to identify vulnerabilities in systems that may be vulnerable to Cloud Atlas attacks. • Utilize secure coding practices, such as input validation and sanitization, to prevent the exploitation of known vulnerabilities like CVE-2018-0802 by malicious actors.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
EquationEquation PowerShowerPowerShower CVE-2018-0802CVE-2018-0802
Target & Sectors
CIS CIS governmentgovernment
Incident Timeline
‎2025/05/22
Threat actors used ReverseSocks to target Cloud Atlas in the second half of 2025 and early 2026.
organisation ReverseSocks
‎late 2025
Threat actors used a new payload to target Russian and Belarusian victims in late 2025.
source_region Russian Federation
source_region Belarus
‎the second half of 2025
Threat actors used a new payload to target Cloud Atlas systems in the second half of 2025.
‎2026/05/22
The attackers used the Cloud Atlas tool, PowerCloud, to target users in the second half of 2025 and early 2026 by sending out malicious ZIP archives containing LNK files as attachments.
infrastructure Windows
organisation PhantomHeart
organisation UAC
organisation RDP
organisation Termsrv.dll
organisation Remote Desktop Services
infrastructure 194.102.104
infrastructure 46.17.45
infrastructure 46.17.44
infrastructure 185.22.154
infrastructure 194.87.196
infrastructure 195.58.49
infrastructure 93.125.114
infrastructure 45.87.219
infrastructure 37.228.129
infrastructure 185.53.179
infrastructure 185.126.239
infrastructure 5.181.21
infrastructure 146.70.53
infrastructure 45.15.65
infrastructure 185.250.181
infrastructure 81.30.105
organisation D3C8AFD22BAA306FF659DB1FAC28574A
organisation Malicious MS Office
organisation IPs
organisation MS Office
organisation amerikastaj[.]com bigbang[.]me
organisation wizzifi[.]com
organisation mamurjor[.]com
organisation internationalcommoditiesllc[.]com
organisation Powershell
organisation ReverseSocks C:\Windows\PLA\System\bounce.exe
organisation VBCloud
organisation Microsoft Office
threat_actor Equation
infrastructure 3 Downloads
organisation Decoy
organisation EDR
infrastructure Winrar
organisation VBScript
organisation VBCloud::Backdoor
organisation Chrome, Edge
organisation syruntime.dll
organisation Tor/SSH/RevSocks
organisation LNK
organisation PDF
organisation DOC
organisation XLS
organisation Conduct “
organisation Active Directory
organisation SAM
organisation SECURITY
organisation B8
organisation SSH
organisation PAExec
organisation PsExec
organisation RevSocks
organisation Reverse SSH
organisation Tor
organisation HiddenService
organisation Google Sheets
‎early 2026
The identified targets were compromised in late 2025 and early 2026, with the malicious activities targeting Russia and Belarus.
source_region Russian Federation
source_region Belarus
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
3
Downloads
Metrics
infrastructure
‎Winrar
Affected Product
Metrics
infrastructure
‎194.102.104
Software Version
Metrics
infrastructure
‎46.17.45
Software Version
Metrics
infrastructure
‎46.17.44
Software Version
Metrics
infrastructure
‎185.22.154
Software Version
Metrics
infrastructure
‎194.87.196
Software Version
Metrics
infrastructure
‎195.58.49
Software Version
Metrics
infrastructure
‎93.125.114
Software Version
Metrics
infrastructure
‎45.87.219
Software Version
Metrics
infrastructure
‎37.228.129
Software Version
Metrics
infrastructure
‎185.53.179
Software Version
Metrics
infrastructure
‎185.126.239
Software Version
Metrics
infrastructure
‎5.181.21
Software Version
Metrics
infrastructure
‎146.70.53
Software Version
Metrics
infrastructure
‎45.15.65
Software Version
Metrics
infrastructure
‎185.250.181
Software Version
Metrics
infrastructure
‎81.30.105
Software Version