CVE-2018-0802
Known exploited · CISA KEV
CVSS 7.8 HIGH: equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016… EPSS 93% (100th percentile).
CISA federal remediation date May 3 · date passed
Threats · 116 days ago
Cloud Atlas is no longer depending on one delivery method or one control channel. It is pairing phishing-delivered ZIP/LNK files that launch PowerShell with older Equation Editor exploitation, then adding Tor, SSH, and RevSocks as backup access so cleanup of one path does not end the intrusion.
Kaspersky says the group is back to archive-based malicious shortcuts and still using CVE-2018-0802 in malicious documents against government and diplomatic targets in Russia and Belarus. The report also identifies new binaries, including loaders and backdoors, and notes ongoing SSH tunnel activity affecting government organizations and commercial companies in both countries.
The practical risk is dwell time. If defenders only remove the first payload or block the first command-and-control route, Cloud Atlas may still keep a foothold and re-enter through alternate channels already planted in the environment.
Known exploited · CISA KEV
CVSS 7.8 HIGH: equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016… EPSS 93% (100th percentile).
CISA federal remediation date May 3 · date passed
1 source covering this story
Cloud Atlas group acquires PowerCloud, ReverseSocks, SSH
Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud.
Part of the PlainSec briefing for 2026-05-23