PowerShower is a PowerShell-based Windows backdoor used by the Cloud Atlas cyberespionage group, also known as Inception. It provides command execution, reconnaissance, document theft, and delivery of additional payloads. Cloud Atlas deploys it through targeted spearphishing campaigns using Microsoft Office document lures that retrieve malicious remote RTF templates. Associated infection chains exploit Microsoft Equation Editor vulnerabilities, including CVE-2017-11882 and CVE-2018-0802. Cloud Atlas campaigns have targeted government, diplomatic, research, industrial, and critical-infrastructure organizations, including entities in Russia, Belarus, Ukraine, and Moldova.
PowerShower receives command-and-control instructions and executes Base64-encoded PowerShell commands delivered in XML. It can download additional content, save and execute VBScript, and deploy reconnaissance modules that enumerate active processes. It identifies the current user and Windows domain. Observed versions use the host's configured proxy and include operating-system and PowerShell version information in HTTP request headers. Base64 encoding and string-concatenation obfuscation conceal scripts and communications. PowerShower has also delivered a script that reflectively loads a .NET relay component associated with Cloud Atlas's proxy infrastructure.
PowerShower establishes persistence through a Registry Run key. Its evasion and cleanup behaviors include modifying console settings so subsequent PowerShell windows open off-screen and removing files and Registry entries created during the dropper stage. A PowerShell document-stealing module collects text, PDF, Excel, and Word documents smaller than 5 MB that were modified within the preceding two days, packs them using 7-Zip, and exfiltrates them.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The remote templates are RTF documents that exploit 5-year-old vulnerabilities in Microsoft Equation Editor, such as CVE-2017-11882 and CVE-2018-0802.
The remote templates are RTF documents that exploit 5-year-old vulnerabilities in Microsoft Equation Editor, such as CVE-2017-11882 and CVE-2018-0802.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The next stage of a Cloud Atlas attack is usually a PowerShell-based backdoor called PowerShower.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
In all cases, the malicious attachment was a document (in either DOC or DOCX format) that implements a Template Injection attack.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used by Cloud Atlas for network reconnaissance, credential access, and theft of files and documents; in this campaign it also loads CloudAtlasGo.
A reconnaissance tool used by Cloud Atlas during post-compromise activity, delivered alongside VBCloud.
Backdoor focused on network reconnaissance and lateral movement. It can collect information on running processes, administrator groups, and domain controllers, download and execute PowerShell scripts from C2, perform Kerberoasting, and load an additional credential-theft script that copies SAM and SECURITY hives using a shadow copy and uses fodhelper.exe for UAC bypass.
Backdoor malware that hides PowerShell windows by forcing off-screen window positioning via registry changes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.