Threats & Adversaries · APT / Espionage

Cloud Atlas Builds Redundant Paths Into Government Networks

Cloud Atlas is no longer depending on one delivery method or one control channel. It is pairing phishing-delivered ZIP/LNK files that launch PowerShell with older Equation Editor exploitation, then adding Tor, SSH, and RevSocks as backup access so cleanup of one path does not end the intrusion.

Kaspersky says the group is back to archive-based malicious shortcuts and still using CVE-2018-0802 in malicious documents against government and diplomatic targets in Russia and Belarus. The report also identifies new binaries, including loaders and backdoors, and notes ongoing SSH tunnel activity affecting government organizations and commercial companies in both countries.

The practical risk is dwell time. If defenders only remove the first payload or block the first command-and-control route, Cloud Atlas may still keep a foothold and re-enter through alternate channels already planted in the environment.

1 source · May 22

CVE-2018-0802

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016… EPSS 93% (100th percentile).

CISA federal remediation date May 3 · date passed

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-23

Every edition of this story: Cloud Atlas Builds Redundant Paths Into Government Networks

More from today