Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
2026-05-27T20:51:53Z•208468532a0ff5d28403164524dc574a43ef2fccf8e2d030b63dc368e5d3f9be
appleseedc2-frameworkscloud atlascve-2025-68670cve-2026-3102edr-killersexiftooliotkimsukylinuxmacosoceanlotuspebbledashpowercloudpyPI supply chainransomwarereverseSockssparkcatsshtortriadavulnerabilitieswindowsxrdpzichatbot
What happened
Kaspersky Securelist (May 2026) collection: multiple investigations and quarterly reports describing active APT campaigns, supply‑chain abuse, and notable vulnerabilities. Highlights include Cloud Atlas targeting Russian/Belarusian public and diplomatic sectors using ReverseSocks, SSH, Tor and a new tool dubbed PowerCloud; an ExifTool vulnerability (CVE-2026-3102) that can compromise macOS via a crafted image; discovery of a pre‑auth RCE in xrdp (CVE-2025-68670) found during assessment of Kaspersky USB Redirector; OceanLotus delivery of ZiChatBot via malicious PyPI wheel packages targeting Win
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 208468532a0ff5d28403164524dc574a43ef2fccf8e2d030b63dc368e5d3f9be
- Enrichment time
- 2026-05-27T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.