VBShower is a Windows VBS-based backdoor associated with the Cloud Atlas espionage group. It functions as a primary launcher and validator component in a multi-stage intrusion chain in which phishing-delivered Microsoft Office documents retrieve a malicious remote template, trigger an HTA payload, and install VBShower. The malware is polymorphic in some observed campaigns, with per-victim variations intended to hinder signature-based detection.
Once installed, VBShower establishes persistence through a Registry Run entry that launches a VBS script at user logon and has been observed restoring its autorun mechanism if removed. It can execute downloaded VBScript payloads, retrieve additional scripts over HTTP, and send execution results back to operator-controlled infrastructure. VBShower has also been used to download and install additional Cloud Atlas malware, including PowerShower, VBCloud, and the CloudAtlas backdoor, making it a central staging component in the group’s toolkit.
The malware includes anti-forensic behavior, notably deleting Office-related temporary files to complicate investigation. Reported follow-on activity enabled by the broader Cloud Atlas toolchain includes system and network reconnaissance, credential theft, file and document theft, and deployment of further post-compromise modules. Victimology linked to campaigns using VBShower includes organizations in Eastern Europe and Central Asia, with repeated targeting of Russian entities and sectors such as government, telecommunications, construction, and industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Заражение происходит через фишинговые электронные письма, содержащие вредоносный документ, который использует уязвимость в редакторе формул (CVE-2018-0802) для загрузки и выполнения вредоносного кода. | Вредоносный HTA-файл извлекает и записывает на диск несколько файлов, являющихся частью бэкдора VBShower, который затем загружает другой бэкдор, PowerShower.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Вредоносный HTA-файл извлекает и записывает на диск несколько файлов, являющихся частью бэкдора VBShower, который затем загружает другой бэкдор, PowerShower.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Many examples describe post-intrusion cleanup, anti-forensics, and removal of artifacts such as logs, scripts, malware components, scheduled tasks, registry keys, and temporary files.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used earlier in the infection chain; dropped by the malicious HTA and used to load PowerShower.
Custom malware delivered after a malicious Word document loads a remote template from C2 and exploits CVE-2018-0802; VBShower is downloaded using alternate data streams.
VBShower is a backdoor used by the Cloud Atlas threat actor, delivered via phishing documents. It downloads and installs other backdoors and can be used to exfiltrate files and gather information.
Primary launcher backdoor used by Cloud Atlas APT to execute downloaded VB scripts and deploy additional payloads. It communicates with command servers to retrieve and execute scripts for file exfiltration, system enumeration, and credential harvesting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.