Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

2026-05-27T20:51:53Z208468532a0ff5d28403164524dc574a43ef2fccf8e2d030b63dc368e5d3f9be
appleseedc2-frameworkscloud atlascve-2025-68670cve-2026-3102edr-killersexiftooliotkimsukylinuxmacosoceanlotuspebbledashpowercloudpyPI supply chainransomwarereverseSockssparkcatsshtortriadavulnerabilitieswindowsxrdpzichatbot

What happened

Kaspersky Securelist (May 2026) collection: multiple investigations and quarterly reports describing active APT campaigns, supply‑chain abuse, and notable vulnerabilities. Highlights include Cloud Atlas targeting Russian/Belarusian public and diplomatic sectors using ReverseSocks, SSH, Tor and a new tool dubbed PowerCloud; an ExifTool vulnerability (CVE-2026-3102) that can compromise macOS via a crafted image; discovery of a pre‑auth RCE in xrdp (CVE-2025-68670) found during assessment of Kaspersky USB Redirector; OceanLotus delivery of ZiChatBot via malicious PyPI wheel packages targeting Win

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
208468532a0ff5d28403164524dc574a43ef2fccf8e2d030b63dc368e5d3f9be
Enrichment time
2026-05-27T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.