Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareUsed by 1 actorExploits 1 CVE

VBCloud

VBCloud is a Windows backdoor and stealer used by the Cloud Atlas espionage group. It has been described as previously undocumented and is deployed in multi-stage phishing-driven intrusion chains, including campaigns using malicious Office documents exploiting CVE-2018-0802 and later campaigns using ZIP archives containing malicious LNK files that launch PowerShell. In observed infections, loader scripts such as fixed.ps1 deliver VBCloud alongside PowerShower, while earlier Cloud Atlas chains used VBShower to install it.

On infected systems, VBCloud is represented by a launcher VBS script and an encrypted main payload, including examples such as video.vbs plus video.mds, or a VBCloud::Launcher and VBCloud::Backdoor pair. The launcher decrypts the encrypted body, typically with RC4 using a hardcoded key, and executes it in memory. VBCloud can establish persistence via scheduled tasks or Run registry entries, and has been observed installed under ProgramData paths themed to legitimate software such as avp, Adobe, Edge, and Chrome directories.

Functionally, VBCloud acts as a backdoor that communicates with attacker infrastructure, receives scripts or commands, and can download and execute additional malicious scripts. A notable characteristic is its use of cloud-based infrastructure and WebDAV rather than only traditional command-and-control servers. Reported behavior includes checking availability of kim.nl.tab.digital and falling back to webdav.mydrive.ch, creating beacon files containing the username and MAC addresses of network adapters, downloading tasking files from cloud directories, deleting those tasking files after retrieval, decrypting them, and executing them in the current process. It maintains encrypted communication with the command server through cloud-based infrastructure.

VBCloud is also used for reconnaissance and data theft. Reported collection includes system and disk information, host and user information, and other system data. As a stealer, it targets files of interest for exfiltration, including extensions such as DOC, DOCX, XLS, XLSX, PDF, TXT, RTF, and RAR, and specifically recent documents. It has also been reported to steal Telegram-related files including D877F783D5D3EF8Cs and key_datas. Exfiltrated data may be packaged into RC4-encrypted ZIP archives and renamed with benign-looking multimedia extensions such as MP3, WAV, OGG, WMA, or MP4.

VBCloud has been associated with Cloud Atlas operations targeting organizations in Eastern Europe and Central Asia, with reporting highlighting victims in Russia and Belarus and sectors including government, diplomatic, telecommunications, construction, and industrial organizations.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2018-0802Microsoft Office Equation Editor Memory Corruption RCEExploited in the wild

Victims get infected via phishing emails containing a malicious document that exploits a vulnerability in the formula editor (CVE-2018-0802) to download and execute malware code.

via securelistsecurelist.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Inception

Besides, they are now using a new module in their attacks: VBCloud. This collects and uploads system information and other data.

via securelistsecurelist.com
MITRE ATT&CK

Techniques & procedures

17 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence2

Victims get infected via phishing emails containing a malicious document that exploits a vulnerability in the formula editor (CVE-2018-0802) to download and execute malware code.

T1566.001Spearphishing AttachmentEvidence1

“Cloud Atlas... using phishing emails bearing malicious Word documents to distribute custom malware known as VBShower and VBCloud.”

Execution

4 techniques
T1053.005Scheduled TaskEvidence1

In the case of VBCloud, the script changes the extension of the unpacked file from TXT to VBS and creates a scheduler task to run VBCloud.

T1059.001PowerShellEvidence3

PowerShower downloads additional PowerShell scripts from the C2 and executes these.

T1059.005Visual BasicEvidence2

VBShower::Launcher ... using the Execute() function to pass control to that file.

T1203Exploitation for Client ExecutionEvidence1

"...malicious document that exploits a vulnerability in the formula editor (CVE-2018-0802) to download and execute malware code"

Persistence

2 techniques
T1053.005Scheduled TaskEvidence1

In the case of VBCloud, the script changes the extension of the unpacked file from TXT to VBS and creates a scheduler task to run VBCloud.

T1547.001Registry Run Keys / Startup FolderEvidence3

After the download is complete, the malware adds a registry key to auto-run the VBShower Launcher script. "Software\Microsoft\Windows\\CurrentVersion\Run"

Privilege Escalation

2 techniques
T1053.005Scheduled TaskEvidence1

In the case of VBCloud, the script changes the extension of the unpacked file from TXT to VBS and creates a scheduler task to run VBCloud.

T1547.001Registry Run Keys / Startup FolderEvidence3

After the download is complete, the malware adds a registry key to auto-run the VBShower Launcher script. "Software\Microsoft\Windows\\CurrentVersion\Run"

Stealth

1 technique
T1221Template InjectionEvidence1

“...the malicious document loads a remote template from C2 specified in one of the document's streams...”

Discovery

3 techniques
T1033System Owner/User DiscoveryEvidence1

Gets the domain, username and computer.

T1082System Information DiscoveryEvidence1

This script gets various system information such as the OS version, RAM size, manufacturer, computer name, username and domain name.

T1083File and Directory DiscoveryEvidence1

Gets information about the file names and sizes in the following folders: %AppData%; %AllUsersProfile%; ...

Collection

2 techniques
T1005Data from Local SystemEvidence3

VBCloud::Payload (2) This script is designed to exfiltrate files and documents. It iterates through local drives and removable media in search of files with the extensions DOC, DOCX, XLS, XLSX, PDF, TXT, RTF and RAR.

T1560Archive Collected DataEvidence1

The script then copies matching files to a ZIP archive it creates, named “mapping.zip”.

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence1

This is the main module that connects to a C2 server to receive additional scripts or execute built-in commands.

T1105Ingress Tool TransferEvidence5

Previously, Cloud Atlas employed PowerShower to download and run an executable file: a DLL library. This DLL would then fetch additional executable modules (plug-ins) from the C2 server and execute these in memory.

Exfiltration

2 techniques
T1041Exfiltration Over C2 ChannelEvidence1

This backdoor is designed to function as a stealer, specifically targeting files with extensions of interest (such as DOC, PDF, XLS) and exfiltrating them.

T1567Exfiltration Over Web ServiceEvidence1

The plugins were downloaded and their output was uploaded via the WebDAV protocol over public cloud services.

INDICATORS OF COMPROMISE

IOCs tracked for this family

38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
31 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
7 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 month ago
ip.v4●●●●●●●●●●●●View more in app1 month ago
ip.v4●●●●●●●●●●●●View more in app1 month ago
ip.v4●●●●●●●●●●●●View more in app1 month ago
ip.v4●●●●●●●●●●●●View more in app1 month ago
ip.v4●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching38

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping17

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

VBCloud | Mallory