# Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain, RevSocks + Reverse SSH Tunnels Targeting Russian and Belarusian Government

> Securelist (Kaspersky) documents an evolved Cloud Atlas (Inception / Clean Ursa / Blue Odin / G0100) APT campaign active in H2 2025 and into early 2026 targeting Russian and Belarusian government, diplomatic, telecommunications and industrial organizations. A spearphishing ZIP -> LNK -> PowerShell chain drops VBCloud (RC4-encrypted VBS backdoor), PowerShower reconnaissance, and PS2EXE-packaged PowerCloud which exfiltrates host telemetry to Google Sheets via authenticated API. Post-exploitation deploys rdp_new.ps1 to byte-patch termsrv.dll on Windows 10 enabling concurrent RDP sessions, RevSocks Go SOCKS proxy for traffic relay, reverse OpenSSH tunnels (patched binaries importing syruntime.dll instead of libcrypto.dll) deployed via PsExec/PAExec + VBS scheduled tasks, and Tor HiddenService forwarding inbound .onion traffic to local 3389.

- **Published:** 2026-05-25T00:00:00Z
- **Last reviewed:** 2026-05-25T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0583
- **ID:** TL-2026-0583
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Inception
- **Detections:** 9 · **IOCs:** 60 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2018-0802

## Description

Cloud Atlas (also tracked as Inception Framework, Clean Ursa, Blue Odin, Oxygen, ATK116, G0100) is a long-running espionage actor active since at least 2014 with historical overlaps to Red October operations. Kaspersky's Securelist team published two reports in 2025-2026 documenting an evolved campaign against Russian and Belarusian state, diplomatic, construction, telecommunications and manufacturing targets. The 2026 reporting extends the established VBCloud / PowerShower toolkit with three significant new capabilities: PowerCloud (PS2EXE-packaged PowerShell agent that exfiltrates Base64-encoded reconnaissance via authenticated Google Sheets API), large-scale operationalization of RevSocks (a public Go SOCKS5 reverse-proxy from github.com/kost/revsocks) as a long-term traffic-relay implant, and a termsrv.dll patch that converts compromised Windows 10 hosts into multi-session RDP servers.

The access chain begins with spearphishing email carrying a ZIP attachment that holds a malicious .lnk shortcut. When opened, the LNK invokes powershell.exe with -ep bypass to fetch a stage-one script (commonly fixed.ps1 written to %TEMP%) which establishes a Run-key persistence value named YandexBrowser_setup under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, drops and opens a decoy PDF from rar.zip via the default handler, then taskkills winrar.exe and cleans up the archive. The earlier H1 2025 wave used CVE-2018-0802 Equation Editor RCE via malicious RTF templates calling powershell.exe -ep bypass -w 01 %APPDATA%\Adobe\AdobeMon.ps1 with persistence stored as Base64 payload inside HKCU\Console\...::WindowPosition registry values and scheduled tasks named MicrosoftEdgeUpdateTask, MicrosoftAdobeUpdateTaskMachine, and MicrosoftVLCTaskMachine.

VBCloud is delivered as a two-stage VBS payload — video.vbs launches and decrypts video.mds, an RC4-encrypted body that stages a file-stealer targeting .doc, .pdf and .xls documents and pulls additional scripts from C2. PowerShower (Securelist S0441) is written to C:\Users\<user>\Pictures\googleearth.ps1 and performs broad host enumeration: running processes, local administrators, domain controllers, plus a fodhelper.exe UAC bypass to trigger SAM/SECURITY hive theft via Volume Shadow Copy with the hives renamed to .pdf in C:\Users\Public\Documents. PowerShower also performs Kerberoasting / AS-REP roasting (T1558.004) for offline cracking. PowerCloud is the 2026 addition — heavily obfuscated PowerShell wrapped into PE form with PS2EXE and dropped to legitimate-looking Windows directories: C:\Windows\wininet.exe, C:\Windows\LiveKernelReports\update.exe, C:\Windows\ime\imejp\dicts\i39884.exe, and C:\Windows\pla\reports.exe. It enumerates local administrators, collects host metadata, Base64 encodes the result and writes it to a Google Sheet via authenticated Google API — a cloud-as-C2 channel that blends with normal corporate traffic and avoids domain-reputation signals.

The centerpiece of the new tradecraft is rdp_new.ps1 (MD5 1A11B26DD0261EF27A112CE8B361C247). The script issues takeown /F C:\Windows\System32\termsrv.dll /A and icacls C:\Windows\System32\termsrv.dll /grant Administrators:F, then patches the byte sequence 39 81 3C 06 00 00 ?? ?? ?? ?? ?? ?? to B8 00 01 00 00 89 81 38 06 00 00 90 inside termsrv.dll. This removes the single-session-per-user restriction enforced by CDFGetBOOLEAN/CDFFinalizeBOOLEAN, allowing concurrent interactive RDP sessions without disconnecting the legitimate user. The script then stops and restarts TermService (sc stop / sc start TermService), adds a Windows Firewall allow rule for TCP/3389 (netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389), and adjusts Terminal Services policy values under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services to relax NLA and remote-connection security. Because the binary file is replaced rather than parameters tweaked, Windows Update may revert the patch on cumulative updates — the operators re-apply as needed.

Long-term access is anchored by three overlapping channels. (1) RevSocks: dropped to C:\Windows\PLA\System\bounce.exe, C:\ProgramData\hp\client.exe, and C:\Windows\System32\timecontrolsvc\vmnetdrv64.exe; it dials out to operator C2 over TLS and exposes the victim network as an attacker-side SOCKS endpoint via flags such as -connect, -fingerprint, and -pass. (2) Reverse OpenSSH tunnels: a patched openssh client (Asset.exe, conhosts.exe, esentprf.exe in legitimate Windows subdirectories) is modified to import syruntime.dll instead of libcrypto.dll. PsExec or PAExec push three VBS launchers — Gen.vbs (WriteToSchedulerGenerateKey.vbs) generates the keypair, Run.vbs (WriteToSchedulerRunSSH.vbs) invokes ssh -R -N -f -i to establish the reverse tunnel, and Kill.vbs (WriteToSchedulerKillSSH.vbs) tears it down on demand. The keys and binaries are protected with restrictive NTFS ACLs. (3) Tor HiddenService: tor binaries dropped as C:\Windows\Resources\Update\Intel.exe and C:\Windows\INF\package.exe configure the host as a hidden service forwarding inbound .onion traffic to localhost:3389, completing a fully Tor-routed RDP path that needs no inbound firewall hole.

A dedicated browser-activity checker (MD5 5329F7BFF9D0D5DB28821B86C26D628F) drops to C:\ProgramData\checker_<random>.exe and watches Chrome, Edge and Firefox processes, logging activity to a local file so operators can time hands-on-keyboard intrusion around periods when the legitimate user is absent. Decoy PDFs themed around Russian/Belarusian government, diplomatic and corporate topics are used to keep the user engaged while the chain unfolds.

C2 and staging infrastructure is broad and well-aged. SSH/RevSocks operations cluster on 46.17.44.0/24 and 46.17.45.0/24 (194.102.104.207, 46.17.45.56, 46.17.45.49, 46.17.44.125, 46.17.44.212) and named hosts tenkoff.org, cloudguide.in, goverru.com, kufar.org, ultimatecore.net, spbnews.net, onedrivesupport.net. Tor and additional C2 IPs include 185.22.154.73, 194.87.196.163, 195.58.49.99, 45.87.219.116, 37.228.129.224, 185.53.179.136, 185.126.239.77, 5.181.21.75, 146.70.53.171, 45.15.65.134, 185.250.181.207, 81.30.105.71 plus AWS-borrowed 3.125.114.193 and 3.125.114.57. Document-exploit delivery has been routed through dozens of compromised legitimate sites (amerikastaj.com, bigbang.me, wizzifi.com, kommando.live, humanitas.si, etc.). The H1 2025 wave used billet-ru.net, mskreg.net, flashsupport.org, solid-logit.com, cityru-travel.org, transferpolicy.org, information-model.net, and securemodem.com as C2.

Detection focus: PowerShell takeown/icacls/byte-patching of termsrv.dll; sudden re-creation of Run-key value YandexBrowser_setup; net stop/start of TermService unrelated to KB activity; firewall rule additions named "RDP" by powershell; SAM/SECURITY hives copied to public paths with .pdf extension; PsExec/PAExec writing VBS to %SYSTEMROOT%\PLA\System, %SYSTEMROOT%\INF, or %SYSTEMROOT%\INF\BITS; outbound TLS from svchost-look-alike paths (PLA\System\bounce.exe, ProgramData\hp\client.exe, timecontrolsvc\vmnetdrv64.exe); openssh client binaries outside standard install paths; Google Sheets API access from non-browser processes; .onion-style local services bound to 3389.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1583 Acquire Infrastructure
- T1584.001 Compromise Infrastructure: Domains
- T1588.002 Obtain Capabilities: Tool
- T1566.001 Phishing: Spearphishing Attachment
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1203 Exploitation for Client Execution
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1505.005 Server Software Component: Terminal Services DLL
- T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
- T1036.005 Match Legitimate Resource Name or Location
- T1070.004 Indicator Removal: File Deletion
- T1686 Disable or Modify System Firewall
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1574.001 DLL
- T1222 File and Directory Permissions Modification
- T1218.005 System Binary Proxy Execution: Mshta
- T1003.002 Security Account Manager
- T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
- T1558.004 Steal or Forge Kerberos Tickets: AS-REP Roasting
- T1082 System Information Discovery
- T1057 Process Discovery
- T1069.002 Permission Groups Discovery: Domain Groups
- T1083 File and Directory Discovery
- T1021.001 Remote Services: Remote Desktop Protocol
- T1021.004 Remote Services: SSH
- T1570 Lateral Tool Transfer
- T1005 Data from Local System
- T1056.004 Input Capture: Credential API Hooking
- T1071.001 Application Layer Protocol: Web Protocols
- T1102.002 Web Service: Bidirectional Communication
- T1090.003 Multi-hop Proxy
- T1090.002 Proxy: External Proxy
- T1573.001 Symmetric Cryptography
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567.002 Exfiltration to Cloud Storage

## Sources

- [Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions on Victim Hosts](https://cybersecuritynews.com/cloud-atlas-apt-group-modifies-termsrv-dll/)
- [Cloud Atlas 2026 — Securelist Analysis](https://securelist.com/cloud-atlas-2026/119895/)
- [Cloud Atlas H1 2025 Campaign — Securelist](https://securelist.com/cloud-atlas-h1-2025-campaign/118517/)
- [Cloud Atlas attacks with new backdoor VBCloud — Securelist](https://securelist.com/cloud-atlas-attacks-with-new-backdoor-vbcloud/115103/)
- [MITRE ATT&CK Group G0100 — Inception](https://attack.mitre.org/groups/G0100/)
- [Malpedia — Inception Framework / Cloud Atlas](https://malpedia.caad.fkie.fraunhofer.de/actor/inception_framework)
- [kost/revsocks — Reverse SOCKS5 Proxy (Go)](https://github.com/kost/revsocks)
- [CVE-2018-0802 — Microsoft Office Equation Editor RCE](https://nvd.nist.gov/vuln/detail/CVE-2018-0802)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0583
