Threat reportAPTTL-2026-0583

Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain, RevSocks + Reverse SSH Tunnels Targeting Russian and Belarusian Government

highACTIVE

Cloud Atlas APT (TL-2026-0583), also tracked as Cloud Atlas H2 2025 Campaign, is a high-severity advanced persistent threat campaign, first published 2026-05-25. It is attributed to Inception with high confidence, affects Microsoft Windows 10, references 1 CVE (CVE-2018-0802), maps to 40 MITRE ATT&CK techniques (T1003.002, T1005, T1021.001), and is covered by 9 detection rules and 60 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
40MITRE ATT&CK
Actors
1Inception
Detection rules
9SPL · KQL · Sigma
IOCs
60Indicators of compromise

Key facts for TL-2026-0583

Threat ID
TL-2026-0583
Also known as
Cloud Atlas H2 2025 Campaign, termsrv.dll Multi-RDP Patch Campaign, PowerCloud Operation
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Inception
Attribution confidence
HIGH
Motivation
ESPIONAGE
Target sectors
government, diplomatic, defense, telecommunications, manufacturing, construction
Target regions
Russia, Belarus, CIS, Eastern Europe
Detection rules
9
Indicators of compromise
60

Malware and tooling in Cloud Atlas APT

Malware and tooling: PowerCloud, PowerShower, VBCloud, PS2EXE, PsExec / PAExec, RevSocks (github.com/kost/revsocks), Tor HiddenService (forward .onion -> 127.0.0.1:3389)

How Cloud Atlas APT works

Securelist (Kaspersky) documents an evolved Cloud Atlas (Inception / Clean Ursa / Blue Odin / G0100) APT campaign active in H2 2025 and into early 2026 targeting Russian and Belarusian government, diplomatic, telecommunications and industrial organizations. A spearphishing ZIP -> LNK -> PowerShell chain drops VBCloud (RC4-encrypted VBS backdoor), PowerShower reconnaissance, and PS2EXE-packaged PowerCloud which exfiltrates host telemetry to Google Sheets via authenticated API. Post-exploitation deploys rdp_new.ps1 to byte-patch termsrv.dll on Windows 10 enabling concurrent RDP sessions, RevSocks Go SOCKS proxy for traffic relay, reverse OpenSSH tunnels (patched binaries importing syruntime.dll instead of libcrypto.dll) deployed via PsExec/PAExec + VBS scheduled tasks, and Tor HiddenService forwarding inbound .onion traffic to local 3389.

Cloud Atlas (also tracked as Inception Framework, Clean Ursa, Blue Odin, Oxygen, ATK116, G0100) is a long-running espionage actor active since at least 2014 with historical overlaps to Red October operations. Kaspersky's Securelist team published two reports in 2025-2026 documenting an evolved campaign against Russian and Belarusian state, diplomatic, construction, telecommunications and manufacturing targets. The 2026 reporting extends the established VBCloud / PowerShower toolkit with three significant new capabilities: PowerCloud (PS2EXE-packaged PowerShell agent that exfiltrates Base64-encoded reconnaissance via authenticated Google Sheets API), large-scale operationalization of RevSocks (a public Go SOCKS5 reverse-proxy from github.com/kost/revsocks) as a long-term traffic-relay implant, and a termsrv.dll patch that converts compromised Windows 10 hosts into multi-session RDP servers.

The access chain begins with spearphishing email carrying a ZIP attachment that holds a malicious .lnk shortcut. When opened, the LNK invokes powershell.exe with -ep bypass to fetch a stage-one script (commonly fixed.ps1 written to %TEMP%) which establishes a Run-key persistence value named YandexBrowser_setup under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, drops and opens a decoy PDF from rar.zip via the default handler, then taskkills winrar.exe and cleans up the archive. The earlier H1 2025 wave used CVE-2018-0802 Equation Editor RCE via malicious RTF templates calling powershell.exe -ep bypass -w 01 %APPDATA%\Adobe\AdobeMon.ps1 with persistence stored as Base64 payload inside HKCU\Console\...::WindowPosition registry values and scheduled tasks named MicrosoftEdgeUpdateTask, MicrosoftAdobeUpdateTaskMachine, and MicrosoftVLCTaskMachine.

VBCloud is delivered as a two-stage VBS payload — video.vbs launches and decrypts video.mds, an RC4-encrypted body that stages a file-stealer targeting .doc, .pdf and .xls documents and pulls additional scripts from C2. PowerShower (Securelist S0441) is written to C:\Users\<user>\Pictures\googleearth.ps1 and performs broad host enumeration: running processes, local administrators, domain controllers, plus a fodhelper.exe UAC bypass to trigger SAM/SECURITY hive theft via Volume Shadow Copy with the hives renamed to .pdf in C:\Users\Public\Documents. PowerShower also performs Kerberoasting / AS-REP roasting (T1558.004) for offline cracking. PowerCloud is the 2026 addition — heavily obfuscated PowerShell wrapped into PE form with PS2EXE and dropped to legitimate-looking Windows directories: C:\Windows\wininet.exe, C:\Windows\LiveKernelReports\update.exe, C:\Windows\ime\imejp\dicts\i39884.exe, and C:\Windows\pla\reports.exe. It enumerates local administrators, collects host metadata, Base64 encodes the result and writes it to a Google Sheet via authenticated Google API — a cloud-as-C2 channel that blends with normal corporate traffic and avoids domain-reputation signals.

The centerpiece of the new tradecraft is rdp_new.ps1 (MD5 1A11B26DD0261EF27A112CE8B361C247). The script issues takeown /F C:\Windows\System32\termsrv.dll /A and icacls C:\Windows\System32\termsrv.dll /grant Administrators:F, then patches the byte sequence 39 81 3C 06 00 00 ?? ?? ?? ?? ?? ?? to B8 00 01 00 00 89 81 38 06 00 00 90 inside termsrv.dll. This removes the single-session-per-user restriction enforced by CDFGetBOOLEAN/CDFFinalizeBOOLEAN, allowing concurrent interactive RDP sessions without disconnecting the legitimate user. The script then stops and restarts TermService (sc stop / sc start TermService), adds a Windows Firewall allow rule for TCP/3389 (netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389), and adjusts Terminal Services policy values under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services to relax NLA and remote-connection security. Because the binary file is replaced rather than parameters tweaked, Windows Update may revert the patch on cumulative updates — the operators re-apply as needed.

Long-term access is anchored by three overlapping channels. (1) RevSocks: dropped to C:\Windows\PLA\System\bounce.exe, C:\ProgramData\hp\client.exe, and C:\Windows\System32\timecontrolsvc\vmnetdrv64.exe; it dials out to operator C2 over TLS and exposes the victim network as an attacker-side SOCKS endpoint via flags such as -connect, -fingerprint, and -pass. (2) Reverse OpenSSH tunnels: a patched openssh client (Asset.exe, conhosts.exe, esentprf.exe in legitimate Windows subdirectories) is modified to import syruntime.dll instead of libcrypto.dll. PsExec or PAExec push three VBS launchers — Gen.vbs (WriteToSchedulerGenerateKey.vbs) generates the keypair, Run.vbs (WriteToSchedulerRunSSH.vbs) invokes ssh -R -N -f -i to establish the reverse tunnel, and Kill.vbs (WriteToSchedulerKillSSH.vbs) tears it down on demand. The keys and binaries are protected with restrictive NTFS ACLs. (3) Tor HiddenService: tor binaries dropped as C:\Windows\Resources\Update\Intel.exe and C:\Windows\INF\package.exe configure the host as a hidden service forwarding inbound .onion traffic to localhost:3389, completing a fully Tor-routed RDP path that needs no inbound firewall hole.

A dedicated browser-activity checker (MD5 5329F7BFF9D0D5DB28821B86C26D628F) drops to C:\ProgramData\checker_<random>.exe and watches Chrome, Edge and Firefox processes, logging activity to a local file so operators can time hands-on-keyboard intrusion around periods when the legitimate user is absent. Decoy PDFs themed around Russian/Belarusian government, diplomatic and corporate topics are used to keep the user engaged while the chain unfolds.

C2 and staging infrastructure is broad and well-aged. SSH/RevSocks operations cluster on 46.17.44.0/24 and 46.17.45.0/24 (194.102.104.207, 46.17.45.56, 46.17.45.49, 46.17.44.125, 46.17.44.212) and named hosts tenkoff.org, cloudguide.in, goverru.com, kufar.org, ultimatecore.net, spbnews.net, onedrivesupport.net. Tor and additional C2 IPs include 185.22.154.73, 194.87.196.163, 195.58.49.99, 45.87.219.116, 37.228.129.224, 185.53.179.136, 185.126.239.77, 5.181.21.75, 146.70.53.171, 45.15.65.134, 185.250.181.207, 81.30.105.71 plus AWS-borrowed 3.125.114.193 and 3.125.114.57. Document-exploit delivery has been routed through dozens of compromised legitimate sites (amerikastaj.com, bigbang.me, wizzifi.com, kommando.live, humanitas.si, etc.). The H1 2025 wave used billet-ru.net, mskreg.net, flashsupport.org, solid-logit.com, cityru-travel.org, transferpolicy.org, information-model.net, and securemodem.com as C2.

Detection focus: PowerShell takeown/icacls/byte-patching of termsrv.dll; sudden re-creation of Run-key value YandexBrowser_setup; net stop/start of TermService unrelated to KB activity; firewall rule additions named "RDP" by powershell; SAM/SECURITY hives copied to public paths with .pdf extension; PsExec/PAExec writing VBS to %SYSTEMROOT%\PLA\System, %SYSTEMROOT%\INF, or %SYSTEMROOT%\INF\BITS; outbound TLS from svchost-look-alike paths (PLA\System\bounce.exe, ProgramData\hp\client.exe, timecontrolsvc\vmnetdrv64.exe); openssh client binaries outside standard install paths; Google Sheets API access from non-browser processes; .onion-style local services bound to 3389.

MITRE ATT&CK techniques used in TL-2026-0583

Credential Access

T1003.002 Security Account Manager; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting; T1558.004 Steal or Forge Kerberos Tickets: AS-REP Roasting

Collection

T1005 Data from Local System; T1056.004 Input Capture: Credential API Hooking

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.004 Remote Services: SSH; T1570 Lateral Tool Transfer

Defense Evasion

T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1218.005 System Binary Proxy Execution: Mshta; T1574.001 DLL

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1505.005 Server Software Component: Terminal Services DLL; T1547.001 Registry Run Keys / Startup Folder

Discovery

T1057 Process Discovery; T1069.002 Permission Groups Discovery: Domain Groups; T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.002 Proxy: External Proxy; T1090.003 Multi-hop Proxy; T1102.002 Web Service: Bidirectional Communication; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography

defense-impairment

T1222 File and Directory Permissions Modification; T1686 Disable or Modify System Firewall

Privilege Escalation

T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Initial Access

T1566.001 Phishing: Spearphishing Attachment

Resource Development

T1583 Acquire Infrastructure; T1584.001 Compromise Infrastructure: Domains; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Cloud Atlas APT

  • Microsoft — Windows 10
    Vulnerable versions: all builds with single-session termsrv.dll
    Fixed in: N/A — patch reverted by attacker
  • Microsoft — Windows Server (RDS / Terminal Services)
    Vulnerable versions: Server 2016; Server 2019; Server 2022
  • Microsoft — Office (Equation Editor)
    Vulnerable versions: pre-KB4011604
    Fixed in: KB4011604

Remediation for Cloud Atlas APT

Patches

  • Apply latest cumulative updates for Windows 10/11 which restore vendor termsrv.dll
  • Patch CVE-2018-0802 Equation Editor (KB4011604) on any legacy Office still in use
  • Update Microsoft Defender / EDR signatures to detect VBCloud, PowerShower, PowerCloud, RevSocks and patched OpenSSH variants

Immediate actions

  • Block all listed C2 IPs and domains at perimeter and DNS RPZ
  • Hunt for HKCU\Software\Microsoft\Windows\CurrentVersion\Run value name 'YandexBrowser_setup' across Windows endpoints
  • Verify integrity of C:\Windows\System32\termsrv.dll on all Windows 10 hosts (compare hash to vendor baseline) and restore from Microsoft if modified
  • Audit for PowerShell processes invoking takeown.exe and icacls.exe against termsrv.dll
  • Search for the file paths in C:\Windows\PLA\System, C:\Windows\INF\BITS, C:\Windows\ime\imejp\dicts, C:\ProgramData\hp listed as IOCs
  • Audit scheduled tasks named MicrosoftEdgeUpdateTask, MicrosoftAdobeUpdateTaskMachine, MicrosoftVLCTaskMachine for non-Microsoft authors
  • Block outbound to Tor known-relay lists from non-admin workstations
  • Reset domain credentials and Kerberos krbtgt twice for any host showing PowerShower / Kerberoasting indicators

Workarounds

  • Set ACLs on termsrv.dll to deny write for SYSTEM (with monitoring exception) so the takeown/icacls patch path is more visible
  • Block inbound 3389 at the host firewall except from a jump-host subnet
  • Disable VBScript execution via FileSystemObject and WScript.Shell where feasible
  • Require signed PowerShell (AllSigned or Constrained Language Mode) for non-admin users

Longer-term hardening

  • Deploy EDR with PowerShell script-block and AMSI logging enabled (T1059.001 visibility)
  • Restrict PsExec/PAExec usage to a named admin tier with WDAC or AppLocker
  • Disable inbound RDP at the host firewall for workstations that do not require it; require RDP-only via gateway with NLA enforced
  • Block egress to *.googleapis.com Sheets API from non-browser processes to prevent cloud-API C2
  • Implement LSA Protection (RunAsPPL) and Credential Guard to mitigate SAM/SECURITY hive theft and Kerberoasting
  • Tier-0 isolation for domain controllers; remove general workstations' ability to reach DCs over 445/135

CVEs associated with Cloud Atlas APT

CVE-2018-0802

Weaknesses (CWE) in Cloud Atlas APT

CWE-269, CWE-426, CWE-552, CWE-829

Timeline of Cloud Atlas APT

  • Cloud Atlas / Inception Framework activity first publicly documented, with infrastructure and code overlaps to the earlier Red October espionage operation.
  • Kaspersky Securelist publishes the first VBCloud backdoor analysis describing the RC4-encrypted VBS payload and CVE-2018-0802 RTF delivery used against Russian/CIS targets.
  • Securelist publishes H1 2025 campaign report — billet-ru.net, mskreg.net and related infrastructure; persistence-as-data inside HKCU\Console::WindowPosition registry values; scheduled tasks MicrosoftEdgeUpdateTask / MicrosoftAdobeUpdateTaskMachine / MicrosoftVLCTaskMachine.
  • Operators begin H2 2025 wave with new ZIP -> LNK -> PowerShell delivery, dropping VBCloud (video.vbs/video.mds) and PowerShower (googleearth.ps1) alongside decoy PDFs themed around Russian/Belarusian government topics.
  • PS2EXE-packaged PowerCloud variants observed dropped to C:\Windows\wininet.exe, C:\Windows\LiveKernelReports\update.exe, C:\Windows\ime\imejp\dicts\i39884.exe, and C:\Windows\pla\reports.exe, exfiltrating Base64-encoded recon via authenticated Google Sheets API.
  • rdp_new.ps1 (MD5 1A11B26DD0261EF27A112CE8B361C247) observed in the wild patching termsrv.dll byte sequence 39 81 3C 06 00 00 ... to B8 00 01 00 00 89 81 38 06 00 00 90, enabling concurrent RDP sessions on compromised Windows 10 hosts.
  • RevSocks Go-based reverse SOCKS5 proxy deployed to long-term victims as C:\Windows\PLA\System\bounce.exe, C:\ProgramData\hp\client.exe, and C:\Windows\System32\timecontrolsvc\vmnetdrv64.exe, providing persistent egress traffic relay.
  • Patched OpenSSH clients importing syruntime.dll deployed with PsExec/PAExec + VBS launchers (Gen.vbs / Run.vbs / Kill.vbs); Tor binaries dropped as C:\Windows\Resources\Update\Intel.exe and C:\Windows\INF\package.exe configure HiddenService forwarding inbound .onion traffic to 127.0.0.1:3389.
  • Securelist publishes the consolidated 2026 report detailing termsrv.dll patch, PowerCloud, RevSocks rollout and reverse SSH / Tor tradecraft with full IOC set.
  • Cyber Security News republishes Securelist findings, summarizing the termsrv.dll multi-RDP technique and accompanying TTPs for the wider defender community.
  • As of 2026-05-29, this Cloud Atlas (G0100/Inception) campaign is ACTIVE — Kaspersky Securelist's 22 May 2026 report documents ongoing H2 2025/early 2026 operations against Russia/Belarus govt with no takedown or arrests. Operators use PowerCloud, RevSocks, reverse SSH/Tor and re-apply the termsrv.dll multi-RDP patch; Kaspersky continues monitoring.

Sources cited for Cloud Atlas APT

Detection coverage for TL-2026-0583

As of 2026-05-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0583 across Splunk SPL, Microsoft KQL and Sigma, covering 60 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
60 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats