Cloud Atlas seen using a new tool in its attacks
SecureList
DECEMBER 23, 2024
All data collected this way is saved in a TMP alternate data stream and forwarded to the C2 server by the VBShower::Backdoor component. The steps performed by the script are most likely needed to check if the backdoor is present and installed correctly.
Let's personalize your content