Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

2026-05-23T08:51:55Zb2d4093002c271292077fb927e648d365b45296289e3bb2ee3e50e7ecca63124
APTAppleSeedC2 frameworksCloud AtlasEDR killersExifToolKimsukyOceanLotusPebbleDashPowerCloudPyPI supply chainRCESparkCatTriadaZiChatBotmacOS compromisemobile malwarepre-auth RCEransomware trendssupply-chainvulnerability researchxrdp

What happened

Kaspersky Securelist published a batch of reports (May 2026) covering active APT campaigns, new malware/tools, and notable vulnerabilities. Key items: Cloud Atlas operations targeting Russian and Belarusian public/diplomatic sectors using ReverseSocks, SSH, Tor and a new payload PowerCloud; an ExifTool flaw (CVE-2026-3102) that can compromise macOS via a malicious image; discovery of a pre-auth RCE in xrdp (CVE-2025-68670); Kimsuky using PebbleDash tools linked to the AppleSeed cluster; OceanLotus delivering ZiChatBot via malicious PyPI wheels; Q1 2026 mobile/non-mobile/IoT threat and exploit/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
b2d4093002c271292077fb927e648d365b45296289e3bb2ee3e50e7ecca63124
Enrichment time
2026-05-23T08:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload · Baitaphish