s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.cloudatlas

📛 Threat Title

Malware family: CloudAtlas

Category: CloudAtlas First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.cloudatlas`. Printable name: CloudAtlas.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.cloudatlas VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.cloudatlas

IOC database

Type
domain
Value
apk.cloudatlas
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.cloudatlas

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.cloudatlas

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The attack's complexity underscores the evolving sophistication of Cloud Atlas' strategies, posing significant threats to organizations, particularly in sectors like industrial enterprises and state-owned companies.

  • web:cloudindustryreview.com

    VBCloud Malware has emerged as a significant threat targeting Russian entities, with the notorious hacking group Cloud Atlas launching a new campaign. This sophisticated malware exploits vulnerabilities in cloud infrastructure to infiltrate systems, steal sensitive data, and disrupt operations. The campaign highlights the increasing focus on cloud-based environments by cybercriminals ...

  • web:cybersecsentinel.com

    The hallmark of Cloud Atlas' operations lies in its layered approach to infection, obfuscation, and data exfiltration. The group has recently integrated the VBCloud backdoor into its arsenal, supplementing its well-documented VBShower and PowerShower malware .

  • web:cybersecuritynews.com

    The Cloud Atlas advanced persistent threat group has continued its sophisticated campaign targeting organizations across Eastern Europe and Central Asia during the first half of 2025, leveraging outdated Microsoft Office vulnerabilities to deliver multiple backdoor implants. This campaign reveals a coordinated effort to establish persistent access and extract sensitive data from high-value ...

  • web:global.ptsecurity.com

    The malware used by Cloud Atlas is becoming more sophisticated and enhanced. The authors would like to thank the incident response and threat intelligence teams of the PT ESC (PT Expert Security Center) for their help in preparing this article. The following sections contain information on all received samples and updated TTPs.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the CloudAtlas malware family including references, samples and yara signatures.

  • web:omarrao.substack.com

    Cloud Atlas is an APT first observed around 2014, known for long-term, targeted cyber-espionage operations. It typically focuses on government, research, and high-value targets, especially in Eastern Europe and Central Asia. In the first half of 2025, Cloud Atlas continued to rely on spear-phishing emails with malicious document attachments that exploit legacy Microsoft Office vulnerabilities ...

  • web:securelist.com

    We continue to monitor activity linked to Cloud Atlas. In a new campaign that began in August 2023, the attackers made changes to their familiar toolkit. This time, instead of an executable library to load malware modules, the group relied on the VBShower backdoor as the loader. Besides, they are now using a new module in their attacks: VBCloud.

  • web:thehackernews.com

    Cloud Atlas exploits CVE-2018-0802 to deploy VBCloud malware , targeting 80% of victims in Russia for data theft, system probing, and Telegram data ext

  • web:www.securityweek.com

    Cloud Security 'Cloud Atlas' Cyberspies Use Polymorphic Malware in Government Attacks The Cloud Atlas threat group has continued conducting cyber espionage operations and its recent attacks have involved a new piece of polymorphic malware .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.