Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
2026-05-26T20:51:57Z•d1c1fb8728941984aa6deff3369d9ba48e5f8c06117a4c515fb5e724aa6bbd68
AppleSeedC2CVE-2025-68670CVE-2026-3102Cloud AtlasEDR-killersExifToolIoTKimsukyOceanLotusPebbleDashPowerCloudPyPI supply-chainReverseSocksSSHSparkCatTorTriadaZiChatBotdata-leaksexploitsmobile malwareransomwarevulnerabilitiesxrdp
What happened
Kaspersky Securelist roundup (May 2026) summarizing multiple threats and research: Cloud Atlas APT activity targeting public-sector and diplomatic targets (using ReverseSocks, SSH, Tor and a new PowerCloud payload); a critical ExifTool flaw (CVE-2026-3102) enabling macOS compromise via malicious images; discovery of a pre-auth RCE in xrdp (CVE-2025-68670); Kimsuky campaigns using PebbleDash tools linked to the AppleSeed cluster; OceanLotus PyPI-based distribution of ZiChatBot droppers; Q1 2026 mobile and non-mobile threat reports (including SparkCat and Triada); ransomware trends for 2026 (EDR
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- d1c1fb8728941984aa6deff3369d9ba48e5f8c06117a4c515fb5e724aa6bbd68
- Enrichment time
- 2026-05-26T20:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.