Cloud Atlas seen using a new tool in its attacks
SecureList
DECEMBER 23, 2024
Introduction Known since 2014, Cloud Atlas targets Eastern Europe and Central Asia. All data collected this way is saved in a TMP alternate data stream and forwarded to the C2 server by the VBShower::Backdoor component. We’re shedding light on a previously undocumented toolset, which the group used heavily in 2024.
Let's personalize your content