Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

2026-05-25T20:51:56Z313c4946afd3cd7b4712d83df0265c750d376882968bae01efde8fd6497aa284
APTAppleSeedCVE-2025-68670CVE-2026-3102Cloud AtlasEDR evasionExifToolIoTKimsukyLinuxOceanLotusPebbleDashPowerCloudPyPI supply-chainWindowsZiChatBotmacOSmobile threatsransomware trendsxrdp

What happened

Collection of Kaspersky Securelist reports (May 2026) covering APT activity, malware trends, and vulnerabilities. Highlights include Cloud Atlas targeting Russian/Belarusian public and diplomatic entities with new persistence/tools (ReverseSocks, SSH, Tor, PowerCloud); an ExifTool vulnerability (CVE-2026-3102) enabling macOS compromise via malicious images; discovery of a pre-auth RCE in xrdp (CVE-2025-68670); OceanLotus using malicious PyPI wheel packages to deliver ZiChatBot; Kimsuky leveraging PebbleDash/AppleSeed tooling; and quarterly reports on mobile, PC/IoT threats, vulnerabilities/exo

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
313c4946afd3cd7b4712d83df0265c750d376882968bae01efde8fd6497aa284
Enrichment time
2026-05-25T20:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload · Baitaphish