CVE-2018-0802
Known exploited · CISA KEV
CVSS 7.8 HIGH: equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016… EPSS 93% (100th percentile).
CISA federal remediation date May 3 · date passed
Threats & Adversaries · APT / Espionage
Cloud Atlas is no longer depending on one delivery method or one control channel. It is pairing phishing-delivered ZIP/LNK files that launch PowerShell with older Equation Editor exploitation, then adding Tor, SSH, and RevSocks as backup access so cleanup of one path does not end the intrusion.
Kaspersky says the group is back to archive-based malicious shortcuts and still using CVE-2018-0802 in malicious documents against government and diplomatic targets in Russia and Belarus. The report also identifies new binaries, including loaders and backdoors, and notes ongoing SSH tunnel activity affecting government organizations and commercial companies in both countries.
The practical risk is dwell time. If defenders only remove the first payload or block the first command-and-control route, Cloud Atlas may still keep a foothold and re-enter through alternate channels already planted in the environment.
1 source · May 22
Known exploited · CISA KEV
CVSS 7.8 HIGH: equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016… EPSS 93% (100th percentile).
CISA federal remediation date May 3 · date passed
Kaspersky Securelist
Cloud Atlas group acquires PowerCloud, ReverseSocks, SSH
Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud.
originalPart of the PlainSec briefing for 2026-05-22
Every edition of this story: Cloud Atlas Builds Redundant Paths Into Government Networks