Home/Threat Actor/Cloud Atlas
Threat Actor

Cloud Atlas

cloud_atlas · russia · active since 2014

Cloud Atlas (Inception / G0100) is a long-running and well-tooled cyber-espionage cluster active since 2014, characterized by a stable spear-phishing - template-injection maldoc - PowerShower - VBShower - cloud-storage-C2 attack chain, and responsible for over a decade of collection against Russian, Belarusian, Kazakh, and (since February 2022) Ukrainian government, military, religious, and industrial-research targets, with state attribution genuinely disputed and the targeting profile inconsistent with sponsorship by any Russian state organ, despite the cluster's conventional placement within the Russia / post-Soviet threat space.

russia confidence: medium 9 aliases MITRE ATT&CK G0100 ↗

Profile

Cloud Atlas (also tracked as Inception, Inception Framework, Oxygen, Clean Ursa, and MITRE ATT&CK G0100) is a long-running cyber-espionage cluster active since at least 2014. The cluster was first publicly documented in December 2014 by Blue Coat Labs ("The Inception Framework") and named "Cloud Atlas" by Kaspersky GReAT in a near- simultaneous publication that argued the operators were the same team behind the earlier Red October / Rocra cluster (2012-2013). Attribution remains genuinely contested. The cluster is conventionally grouped within the Russia / post-Soviet threat space and is often described as "Russia-aligned" in vendor reporting, primarily because of code, tradecraft, and language-artifact overlap with the earlier Red October cluster. However, Cloud Atlas's victimology has from the outset included heavy targeting of Russian federal government, Russian Orthodox Church entities, Russian military and industrial- research organizations, and Belarusian and Kazakh state targets, with intensifying Ukraine focus since February 2022. This victim profile is inconsistent with sponsorship by any Russian state organ and is more consistent with an external service operating against Russia and its near-abroad. Several analysts have proposed alternative attributions (variously South Asian, Central Asian, or Western-allied); no consensus exists. No state has issued a formal attribution. The "Russia-aligned" framing in this record should be read as "operates in the Russia threat space" rather than as sponsorship by Moscow. Operationally Cloud Atlas is recognized by a stable, distinctive multi-stage attack chain that has survived more than a decade of iteration. Initial access is overwhelmingly via spear-phishing with a weaponized Office document.

from late-2019 onward the dominant delivery is template-injection (T1221) using a remote OLE reference that fetches the malicious template only when the lure is opened on a network-connected host, which suppresses sandbox detonation. Where exploitation is needed, the cluster has favored long-lived Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0802) and earlier CVE-2012-0158 against unpatched MS Office installations. First-stage payload is typically a VBScript dropper that decodes and stages PowerShower (a PowerShell downloader) which in turn retrieves the second-stage VBShower implant family. C2 is famously routed through legitimate cloud-storage and WebDAV providers (originally CloudMe, the source of the cluster's name, and over time also OpenDrive, pCloud, Yandex Disk, Dropbox, Mega), which provides plausible egress and complicates infrastructure takedowns. In May 2023 Kaspersky disclosed CloudWizard, a modular espionage framework with at least nine functional modules (file collection, keylogging, screen capture, microphone recording, USB-device collection, Gmail data theft, etc.) that had been active since 2017 and remained undetected for over five years. CloudWizard was attributed to Cloud Atlas via code overlap with PowerMagic and CommonMagic from the October 2022 BadMagic campaign in Russian- occupied Donbas. CloudWizard substantially raised the assessed sophistication of the cluster and demonstrated parallel maintenance of multiple toolkits over many years. Cloud Atlas continues active operations into 2024-2025 with sustained campaigns against Russia, Belarus, and Ukraine in parallel. Tooling continues to evolve incrementally.

the attribution question remains open.

Aliases

9
cloud atlascloudatlasinceptioninception frameworkoxygenclean ursaatk 116g0100red october successor

Notable Campaigns

9
2024-2025Continued Operations (2024-2025)
2023CloudWizard Framework Disclosure (Kaspersky, May 2023)
2022-2024Ukraine Intensification (February 2022 onward)
2022BadMagic / CommonMagic Donbas Campaign (October 2022)
2020-2021Industrial-Research and Government Targeting (2020-2021)
2019PowerShower Revived Activity (October 2019)
2015-2018Long-Running Collection Campaigns (2015-2018)
2014Inception Framework Disclosure (December 2014)
2014Kaspersky Names Cloud Atlas / Red October Successor (December 2014)

Attribution & Reporting

Attributed by
Kaspersky GReATBlue Coat (Symantec)Palo Alto Networks Unit 42Check Point ResearchProofpointQiAnXin RedDripPositive TechnologiesGroup-IBTrellix (FireEye legacy)PT Expert Security CenterCERT-UAF-Secure / WithSecureESETCisco TalosRecorded Future Insikt Group
Key reporting
reportBlue Coat Labs: The Inception Framework, Cloud-Hosted Backdoor Infrastructure (December 9, 2014)
reportKaspersky GReAT: Cloud Atlas, Red October APT is Back in Style (December 10, 2014)
reportProofpoint: Inception Framework Targeting Defense, Energy and Aerospace (March 2018)
reportESET: Inception Attackers Target Europe with Year-Old Office Vulnerability (March 9, 2018)
reportPalo Alto Networks Unit 42: Cloud Atlas Rebirth via PowerShower (October 2019)
reportCheck Point Research: Cloud Atlas Keeps Some of Its Old Shells (December 2020)
reportPositive Technologies PT ESC: Cloud Atlas Pivot to Russia (August 2019)
reportCisco Talos: Cloud Atlas Targets Russia (August 2019)
reportKaspersky GReAT: Recent Cloud Atlas Activity (August 2019)
reportKaspersky GReAT: Bad Magic, New APT Found in the Area of Russia-Ukraine Conflict (March 21, 2023)
reportKaspersky GReAT: CloudWizard APT, The Bad Magic Story Goes On (May 19, 2023)
reportGroup-IB: Cloud Atlas / Inception Cluster Tracking (2022)
reportFortinet FortiGuard Labs: Cloud Atlas Maldoc Targets Russian Agro and Research Holdings (December 2022)
reportCERT-UA Advisories on Cloud Atlas / UAC-0163 Activity Against Ukrainian Targets (2022-2024)
reportBleeping Computer: Cloud Atlas Hackers Target Russian Companies with New Backdoor (December 2022)
reportMalpedia Actor Profile: Cloud Atlas
reportMITRE ATT&CK Group G0100, Inception

Operational

State sponsor

Disputed / publicly contested. No formal government attribution has been issued by any state. The cluster has been characterized as "Russia-aligned" by some vendor research (notably Kaspersky GReAT, which observed code-base and target-profile overlap with the earlier Red October / Rocra cluster that is widely assessed as Russia-aligned).

However, Cloud Atlas's observed victimology, heavy targeting of Russia, Belarus, Kazakhstan, Kyrgyzstan, and the wider post-Soviet space, with intensifying focus on Russian federal government, military, religious, and industrial-research organizations from 2019 onward, and pronounced Ukraine targeting since February 2022, is inconsistent with sponsorship by any Russian state organ and more consistent with an external intelligence service operating against Russian and post-Soviet targets. Several analysts have therefore proposed alternative attributions (South Asian, Central Asian, or Western-aligned), but none has reached consensus. The handoff and the project's existing geopolitical groupings retain the conventional "Russia-space" label, which here should be read as "operates within the Russia / former-Soviet threat space" rather than "sponsored by the Russian state." Treat attribution as actively open.

Motivations
espionage, intelligence_gathering, geopolitical_collection, long_dwell_access
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)53/60 · 88%
Analytics (MITRE CAR)26/60 · 43%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)12/60 · 20%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTA
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin