Palo Alto Networks has identified spear-phishing campaigns related to Russia, Central Asia and regions of Ukraine with ongoing military conflicts. Inception, Cloud Atlas is an actor that has a long history of cyber-espionage operations targeting industries and governmental entities. Cloud Atlas hasnt changed its TTPs (Tactic Tools and Procedures) since 2018 and is still relying on its effective existing tactics and malware in order to compromise high value targets. In recent months, we have seen a new infection chain involving a polymorphic HTA, a new and polymorphic VBS implant aimed at executing PowerShower and the Cloud Atlas second stage modular backdoor.”]
Source: https://securelist.com/recent-cloud-atlas-activity/92016/