Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
2026-05-25T20:51:56Z•313c4946afd3cd7b4712d83df0265c750d376882968bae01efde8fd6497aa284
APTAppleSeedCVE-2025-68670CVE-2026-3102Cloud AtlasEDR evasionExifToolIoTKimsukyLinuxOceanLotusPebbleDashPowerCloudPyPI supply-chainWindowsZiChatBotmacOSmobile threatsransomware trendsxrdp
What happened
Collection of Kaspersky Securelist reports (May 2026) covering APT activity, malware trends, and vulnerabilities. Highlights include Cloud Atlas targeting Russian/Belarusian public and diplomatic entities with new persistence/tools (ReverseSocks, SSH, Tor, PowerCloud); an ExifTool vulnerability (CVE-2026-3102) enabling macOS compromise via malicious images; discovery of a pre-auth RCE in xrdp (CVE-2025-68670); OceanLotus using malicious PyPI wheel packages to deliver ZiChatBot; Kimsuky leveraging PebbleDash/AppleSeed tooling; and quarterly reports on mobile, PC/IoT threats, vulnerabilities/exo
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 313c4946afd3cd7b4712d83df0265c750d376882968bae01efde8fd6497aa284
- Enrichment time
- 2026-05-25T20:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.