Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
2026-05-23T08:51:55Z•b2d4093002c271292077fb927e648d365b45296289e3bb2ee3e50e7ecca63124
APTAppleSeedC2 frameworksCloud AtlasEDR killersExifToolKimsukyOceanLotusPebbleDashPowerCloudPyPI supply chainRCESparkCatTriadaZiChatBotmacOS compromisemobile malwarepre-auth RCEransomware trendssupply-chainvulnerability researchxrdp
What happened
Kaspersky Securelist published a batch of reports (May 2026) covering active APT campaigns, new malware/tools, and notable vulnerabilities. Key items: Cloud Atlas operations targeting Russian and Belarusian public/diplomatic sectors using ReverseSocks, SSH, Tor and a new payload PowerCloud; an ExifTool flaw (CVE-2026-3102) that can compromise macOS via a malicious image; discovery of a pre-auth RCE in xrdp (CVE-2025-68670); Kimsuky using PebbleDash tools linked to the AppleSeed cluster; OceanLotus delivering ZiChatBot via malicious PyPI wheels; Q1 2026 mobile/non-mobile/IoT threat and exploit/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- b2d4093002c271292077fb927e648d365b45296289e3bb2ee3e50e7ecca63124
- Enrichment time
- 2026-05-23T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.