Cloud Atlas, also known as Inception and Inception Framework, is a cyberespionage threat group active since at least 2014. It targets government ministries, diplomatic organizations, research institutions, industrial enterprises, and critical infrastructure. Documented targets include organizations in Russia, Belarus, Ukraine, Moldova, Azerbaijan, Turkey, and Slovenia. Its targeting has included transportation, military radio-electronics, energy, metals, and agricultural organizations. Its country of origin and state sponsor have not been established. The group primarily obtains initial access through tailored spearphishing emails carrying malicious Microsoft Office documents. Lures draw on government publications, geopolitical developments, and recipients’ professional responsibilities, sometimes impersonating trusted organizations. Documents retrieve remote RTF templates that exploit Microsoft Equation Editor vulnerabilities, including CVE-2017-11882 and CVE-2018-0802. Reconnaissance documents and victim-specific restrictions on payload delivery help identify intended targets and hinder analysis. Subsequent stages use HTA, VBScript, PowerShell, and .NET loaders, including the PowerShower backdoor. Cloud Atlas maintains a modular espionage framework that collects host information, searches for documents and other files on local disks, removable media, and network locations, and steals browser passwords, cookies, and session data. It has also used the open-source credential-recovery tool LaZagne. The group abuses OpenDrive through WebDAV for command and control, module delivery, and data exfiltration, and uses HTTP and HTTPS in other infection chains. Its infrastructure includes multi-hop proxy chains of compromised routers and the RtcpProxy relay tool. Defense-evasion techniques include AES and RC4 payload encryption, script obfuscation, polymorphic code, in-memory loading, concealment in NTFS alternate data streams, and artifact removal. Persistence is established through Registry autorun entries, with execution involving Windows scripting utilities and signed system binaries.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
The remote templates are RTF documents that exploit 5-year-old vulnerabilities in Microsoft Equation Editor, such as CVE-2017-11882 and CVE-2018-0802.
The remote templates are RTF documents that exploit 5-year-old vulnerabilities in Microsoft Equation Editor, such as CVE-2017-11882 and CVE-2018-0802.
In August 2014, some of our users observed targeted attacks with a variation of CVE-2012-0158 and an unusual set of malware.
Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
370 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used Microsoft Equation Editor exploitation to deliver the CloudAtlasGo malware.
Used malicious Office documents to exploit a Microsoft Office vulnerability and deliver the CloudAtlasGo payload for espionage-oriented access.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.