Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

2026-05-26T20:51:57Zd1c1fb8728941984aa6deff3369d9ba48e5f8c06117a4c515fb5e724aa6bbd68
AppleSeedC2CVE-2025-68670CVE-2026-3102Cloud AtlasEDR-killersExifToolIoTKimsukyOceanLotusPebbleDashPowerCloudPyPI supply-chainReverseSocksSSHSparkCatTorTriadaZiChatBotdata-leaksexploitsmobile malwareransomwarevulnerabilitiesxrdp

What happened

Kaspersky Securelist roundup (May 2026) summarizing multiple threats and research: Cloud Atlas APT activity targeting public-sector and diplomatic targets (using ReverseSocks, SSH, Tor and a new PowerCloud payload); a critical ExifTool flaw (CVE-2026-3102) enabling macOS compromise via malicious images; discovery of a pre-auth RCE in xrdp (CVE-2025-68670); Kimsuky campaigns using PebbleDash tools linked to the AppleSeed cluster; OceanLotus PyPI-based distribution of ZiChatBot droppers; Q1 2026 mobile and non-mobile threat reports (including SparkCat and Triada); ransomware trends for 2026 (EDR

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
d1c1fb8728941984aa6deff3369d9ba48e5f8c06117a4c515fb5e724aa6bbd68
Enrichment time
2026-05-26T20:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.