TF-MAL-apk.cloudatlas
📛 Threat Title
Malware family: CloudAtlas
Description
ThreatFox malware family `apk.cloudatlas`. Printable name: CloudAtlas.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.cloudatlas
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.cloudatlas
IOC database
- Type
- domain
- Value
apk.cloudatlas- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.cloudatlas
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.cloudatlas
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The attack's complexity underscores the evolving sophistication of Cloud Atlas' strategies, posing significant threats to organizations, particularly in sectors like industrial enterprises and state-owned companies.
-
web:cloudindustryreview.com
VBCloud Malware has emerged as a significant threat targeting Russian entities, with the notorious hacking group Cloud Atlas launching a new campaign. This sophisticated malware exploits vulnerabilities in cloud infrastructure to infiltrate systems, steal sensitive data, and disrupt operations. The campaign highlights the increasing focus on cloud-based environments by cybercriminals ...
-
web:cybersecsentinel.com
The hallmark of Cloud Atlas' operations lies in its layered approach to infection, obfuscation, and data exfiltration. The group has recently integrated the VBCloud backdoor into its arsenal, supplementing its well-documented VBShower and PowerShower malware .
-
web:cybersecuritynews.com
The Cloud Atlas advanced persistent threat group has continued its sophisticated campaign targeting organizations across Eastern Europe and Central Asia during the first half of 2025, leveraging outdated Microsoft Office vulnerabilities to deliver multiple backdoor implants. This campaign reveals a coordinated effort to establish persistent access and extract sensitive data from high-value ...
-
web:global.ptsecurity.com
The malware used by Cloud Atlas is becoming more sophisticated and enhanced. The authors would like to thank the incident response and threat intelligence teams of the PT ESC (PT Expert Security Center) for their help in preparing this article. The following sections contain information on all received samples and updated TTPs.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the CloudAtlas malware family including references, samples and yara signatures.
-
web:omarrao.substack.com
Cloud Atlas is an APT first observed around 2014, known for long-term, targeted cyber-espionage operations. It typically focuses on government, research, and high-value targets, especially in Eastern Europe and Central Asia. In the first half of 2025, Cloud Atlas continued to rely on spear-phishing emails with malicious document attachments that exploit legacy Microsoft Office vulnerabilities ...
-
web:securelist.com
We continue to monitor activity linked to Cloud Atlas. In a new campaign that began in August 2023, the attackers made changes to their familiar toolkit. This time, instead of an executable library to load malware modules, the group relied on the VBShower backdoor as the loader. Besides, they are now using a new module in their attacks: VBCloud.
-
web:thehackernews.com
Cloud Atlas exploits CVE-2018-0802 to deploy VBCloud malware , targeting 80% of victims in Russia for data theft, system probing, and Telegram data ext
-
web:www.securityweek.com
Cloud Security 'Cloud Atlas' Cyberspies Use Polymorphic Malware in Government Attacks The Cloud Atlas threat group has continued conducting cyber espionage operations and its recent attacks have involved a new piece of polymorphic malware .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.