Cloud Atlas Builds Redundant Paths Into Government Networks
Cloud Atlas is no longer depending on one delivery method or one control channel. It is pairing phishing-delivered ZIP/LNK files that launch PowerShell with older Equation Editor exploitation, then adding Tor, SSH, and RevSocks as backup access so cleanup of one path does not end the intrusion.
Kaspersky says the group is back to archive-based malicious shortcuts and still using CVE-2018-0802 in malicious documents against government and diplomatic targets in Russia and Belarus. The report also identifies new binaries, including loaders and backdoors, and notes ongoing SSH tunnel activity affecting government organizations and commercial companies in both countries.
The practical risk is dwell time. If defenders only remove the first payload or block the first command-and-control route, Cloud Atlas may still keep a foothold and re-enter through alternate channels already planted in the environment.