Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
2026-05-22T20:52:00Z•c7a6f1d76b7c472c65aa99657be7eb51f4160fe9d1ca4fbb2a38b915a015f180
AppleSeedCVE-2025-68670CVE-2026-3102Cloud AtlasEDR-killersExifToolIoTKimsukyLinuxOceanLotusPebbleDashPowerCloudPyPI supply-chainReverseSocksSSHSparkCatTorTriadaWindowsZiChatBotdata-exfiltrationmacOSmobileransomwarexrdp
What happened
Kaspersky Securelist feed (May 2026) covering active APT campaigns, new malware and supply‑chain abuse, and vulnerability disclosures. Highlights include Cloud Atlas activity in late 2025–early 2026 using ReverseSocks, SSH and Tor and a new PowerCloud payload targeting Russian and Belarusian public/diplomatic networks; an ExifTool macOS RCE (CVE-2026-3102) enabling compromise via malicious images; discovery of a pre‑auth xrdp RCE (CVE-2025-68670); OceanLotus-distributed ZiChatBot via malicious PyPI wheels; Kimsuky using PebbleDash linked to the AppleSeed cluster; Q1 2026 mobile, PC and IoT/mal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- c7a6f1d76b7c472c65aa99657be7eb51f4160fe9d1ca4fbb2a38b915a015f180
- Enrichment time
- 2026-05-22T20:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.