CloudAtlas: A new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
CloudAtlas: a new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources
In May 2026, the Threat Intelligence department of Positive Technologies’ Expert Security Center identified a new campaign by the APT group CloudAtlas. Russian organizations in the energy, defense-industrial, and transportation sectors were targeted, primarily located on the territory of the Crimean peninsula.
📄 The group used Microsoft Office documents whose malicious templates were downloaded from compromised legitimate resources in the national domain zones of Brazil, Argentina, and Indonesia. The PT ESC cyberthreat intelligence team previously reported on the use of this technique in a study of the connection between the CloudAtlas group and the initial access broker Mustard Tempest.
Opening the documents triggered a multi-stage chain of HTA and VBS components that extracted encoded VBS loader code from a JFM file. At the final stage, the VBShower and PowerCloud loaders were deployed, using Google Sheets as a communication channel with C2. A separate VBS script wiped traces of the compromise.
🚂🚃👾🚃🚃 The key innovation of the campaign was the use of chains of legitimate resources that served as a transport layer for delivering the payload. Instead of direct HTTP requests to compromised web resources, the group used oEmbed requests to deliver the payload through intermediary legitimate WordPress sites with open API endpoints. This technique made it possible to mask network connections as legitimate traffic and complicate signature-based detection.
[LEGITIMATE_DOMAIN]/?wp-json/oembed/1.0/embed/url=[COMPROMISED_DOMAIN_URL]
To exfiltrate information about the user and domain of the compromised host, the group used the User-Agent HTTP header in network connections with C2.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ([USERDOMAIN], like [USERNAME]) Chrome/141.0.0.0 Safari/537.36 Edg/141.0.3405.86
Another feature of the campaign was its geographic focus: some of the documents used appear by external signs to be intended for an audience in Iraq, which is an atypical geography for cyberattacks by the CloudAtlas group.
👉 Read more in the study on our website and in the blog on Habr.
#TI #APT #CloudAtlas
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



