Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

2026-05-22T20:52:00Zc7a6f1d76b7c472c65aa99657be7eb51f4160fe9d1ca4fbb2a38b915a015f180
AppleSeedCVE-2025-68670CVE-2026-3102Cloud AtlasEDR-killersExifToolIoTKimsukyLinuxOceanLotusPebbleDashPowerCloudPyPI supply-chainReverseSocksSSHSparkCatTorTriadaWindowsZiChatBotdata-exfiltrationmacOSmobileransomwarexrdp

What happened

Kaspersky Securelist feed (May 2026) covering active APT campaigns, new malware and supply‑chain abuse, and vulnerability disclosures. Highlights include Cloud Atlas activity in late 2025–early 2026 using ReverseSocks, SSH and Tor and a new PowerCloud payload targeting Russian and Belarusian public/diplomatic networks; an ExifTool macOS RCE (CVE-2026-3102) enabling compromise via malicious images; discovery of a pre‑auth xrdp RCE (CVE-2025-68670); OceanLotus-distributed ZiChatBot via malicious PyPI wheels; Kimsuky using PebbleDash linked to the AppleSeed cluster; Q1 2026 mobile, PC and IoT/mal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
c7a6f1d76b7c472c65aa99657be7eb51f4160fe9d1ca4fbb2a38b915a015f180
Enrichment time
2026-05-22T20:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.