[ << ALL_FEED ]

CloudAtlas: A new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources

More in General

CloudAtlas: a new wave of cyberattacks on organizations in Russia and Iraq using chains of legitimate web resources

In May 2026, the Threat Intelligence department of Positive Technologies’ Expert Security Center identified a new campaign by the APT group CloudAtlas. Russian organizations in the energy, defense-industrial, and transportation sectors were targeted, primarily located on the territory of the Crimean peninsula.

📄 The group used Microsoft Office documents whose malicious templates were downloaded from compromised legitimate resources in the national domain zones of Brazil, Argentina, and Indonesia. The PT ESC cyberthreat intelligence team previously reported on the use of this technique in a study of the connection between the CloudAtlas group and the initial access broker Mustard Tempest.

Opening the documents triggered a multi-stage chain of HTA and VBS components that extracted encoded VBS loader code from a JFM file. At the final stage, the VBShower and PowerCloud loaders were deployed, using Google Sheets as a communication channel with C2. A separate VBS script wiped traces of the compromise.

🚂🚃👾🚃🚃 The key innovation of the campaign was the use of chains of legitimate resources that served as a transport layer for delivering the payload. Instead of direct HTTP requests to compromised web resources, the group used oEmbed requests to deliver the payload through intermediary legitimate WordPress sites with open API endpoints. This technique made it possible to mask network connections as legitimate traffic and complicate signature-based detection.

[LEGITIMATE_DOMAIN]/?wp-json/oembed/1.0/embed/url=[COMPROMISED_DOMAIN_URL]

To exfiltrate information about the user and domain of the compromised host, the group used the User-Agent HTTP header in network connections with C2.

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ([USERDOMAIN], like [USERNAME]) Chrome/141.0.0.0 Safari/537.36 Edg/141.0.3405.86

Another feature of the campaign was its geographic focus: some of the documents used appear by external signs to be intended for an audience in Iraq, which is an atypical geography for cyberattacks by the CloudAtlas group.

👉 Read more in the study on our website and in the blog on Habr.

#TI #APT #CloudAtlas
@ptescalator

More from ti_author

More from ti_author

More in General