Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
Reported exploitedVBCloudCloud AtlasPowerShower Read at Kaspersky Securelist
Below is the opening; the full story is at Kaspersky Securelist.
From Kaspersky Securelist
In 2025, we observed pervasive SSH tunnel activity, which has remained active into 2026, affecting many government organizations and commercial companies in Russia and Belarus. Behind some of this activity is Cloud Atlas, a group we have known since 2014. During our investigation, we identified new tools used by this group, as well as indicators of compromise.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.