[ << ALL_FEED ]

APT group Cloud Atlas attacks Russian defense industry enterprises

More in General

APT group Cloud Atlas attacks Russian defense industry enterprises 🌎

At the end of last year and the beginning of this year, a cyber intelligence group discovered the migration of command infrastructure and the evolution of malicious documents in Cloud Atlas’s arsenal, marking the start of a new campaign by the group targeting enterprises of Russia’s defense industrial complex.

Monitoring the identified malicious infrastructure made it possible to track in real time the full scope of Cloud Atlas’s new cyber activity, including uncovering BEC attacks using the email of previously infected Russian defense industry enterprises to send malicious Microsoft Office documents to counterparties.

📫 The initial intrusion vector traditionally involved phishing emails with malicious Microsoft Office documents attached. Information about the command infrastructure and malicious VB scripts was hidden in the alternate data stream (1Table) of the documents. Opening the files triggered the execution of these scripts, which interacted with the Google Sheets API to transmit information about the infected system and download the PowerShower backdoor, followed by exfiltration of stolen data to cloud storage (more details in our previous research).

In terms of content, the malicious attachments were invitations to advanced training courses, documents on anti-corruption audits and mobilization activities, reconciliation of mutual settlements, employee references, and resumes of applicants for CNC operator positions.

🤷‍♂️ The discovered documents — mostly templates typical of the public sector — are not publicly available and were most likely stolen from the networks of previously attacked enterprises. To avoid exposing the enterprises whose networks the group had compromised, metadata was removed from the infected documents before their use in new attacks, as evidenced by their modification timestamps.

The activity of the APT group Cloud Atlas has been tracked since 2014. The traditional geography of attacks is the CIS countries. In 2024, the vector of cyberattacks shifted significantly toward Russia, and their high intensity, the frequency of attacker infrastructure migration, and the evolution of malicious documents persist to this day.

A high level of cyber threat danger is forecast for Russian institutions and organizations originating from the APT group Cloud Atlas.

🧐 Read more on our website.

#TI #APT #Malware
@ptescalator

More from ti_author

More from ti_author

More in General