Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

2026-05-26T08:51:58Zb31f7063222e1859ab472cf17310c1510d0d9481b3223e3046f460bc62a1217e
AppleSeedCloud AtlasEDR-killersExifToolIoTKimsukyLinuxOceanLotusPebbleDashPowerCloudPyPIReverseSocksSSHSparkCatTorTriadaWindowsZiChatBotimage parsingmacOSmobile malwareransomwaresupply-chainvulnerabilitiesxrdp

What happened

Kaspersky Securelist (May 2026) highlights multiple high-risk threats and research: Cloud Atlas (targeting Russian/Belarusian public and diplomatic sectors) expanded persistence tooling (ReverseSocks, SSH, Tor) and introduced a new loader PowerCloud; an ExifTool vulnerability (CVE-2026-3102) enables macOS compromise via crafted images; a pre-auth RCE in xrdp was reported as CVE-2025-68670; OceanLotus abused PyPI with malicious wheels delivering ZiChatBot; Kimsuky used PebbleDash-based tools linked to the AppleSeed cluster; Q1 2026 reports summarize mobile (SparkCat, Triada), PC/macOS and IoT,+

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
b31f7063222e1859ab472cf17310c1510d0d9481b3223e3046f460bc62a1217e
Enrichment time
2026-05-26T08:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.