ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Cloud Atlas using a new backdoor, VBCloud, to steal data

highMalwareimportance 47CVE-2018-0802

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0802
Memory Corruption RCE in Microsoft Office Equation Editor

A memory-corruption flaw (out-of-bounds write, CWE-787) in the legacy Equation Editor component (EQNEDT32.EXE) shipped with Microsoft Office 2007, 2010, 2013, and 2016 allows remote code execution due to improper handling of objects in memory. An attacker triggers it by persuading a user to open a specially crafted document (for example an RTF or DOCX containing a malformed embedded equation object), causing the Equation Editor process to corrupt memory when the file is opened in Word; the user-interaction requirement is reflected in the CVSS 3.1 vector (AV:L/UI:R). Successful exploitation gives the attacker code execution in the context of the current user, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8, High). Any user of the affected Office versions, the Office Compatibility Pack, or Word on an unpatched system is affected. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, carries a 93.3% EPSS probability of exploitation within 30 days, and multiple public analyses and proof-of-concepts exist.

Do: Apply Microsoft's January 2018 security updates for Office 2007, 2010, 2013, and 2016 and the Office Compatibility Pack, and verify the legacy Equation Editor executable (EQNEDT32.EXE) on endpoints has been patched or removed (Microsoft later retired the component). Because the flaw is exploited in the wild and used in ransomware campaigns, prioritize remediation per CISA KEV required action and hunt for Word spawning EQNEDT32.EXE or unexpected child processes when documents are opened. Until patched, open untrusted documents in Protected View and treat email-delivered RTF/DOCX attachments as untrusted.

7.893% KEV ransomware PoC ×3
  • Microsoft Office Office 2007, Office 2010, Office 2013, Office 2016 (Equation Editor component)
  • Microsoft Office Compatibility Pack
  • Microsoft Word
masshundreds of millions of Office users at time of disclosure (vulnerable Equation Editor shipped by default with Office 2007-2016); largely patched today, with…

Indicators of compromiseAll →

TypeIndicatorContext
domaincontent-protect.nety GReAT. Indicators of compromise HTA file download domains content-protect[.]net control-issue[.]net office-confirm[.]com onesoftware[.]in
domaincontrol-issue.netcompromise HTA file download domains content-protect[.]net control-issue[.]net office-confirm[.]com onesoftware[.]info serverop-parametr
domaingosportal.netks[.]net yandisk[.]info mirconnect[.]info sber-cloud[.]info gosportal[.]net riamir[.]net web-wathapp[.]com PowerShower C2 yandisk[.]i
domainkim.nl.tab.digitalt VBCloud does the following: Check the availability of the kim.nl.tab.digital WebDav server by sending an HTTP MKCOL request to create th
domainmirconnect.infoger-working[.]com VBShower C2 yandesks[.]net yandisk[.]info mirconnect[.]info sber-cloud[.]info gosportal[.]net riamir[.]net web-wathap
domainnet-plugin.orgesoftware[.]info serverop-parametrs[.]com web-privacy[.]net net-plugin[.]org triger-working[.]com VBShower C2 yandesks[.]net yandisk[.
domainoffice-confirm.comdownload domains content-protect[.]net control-issue[.]net office-confirm[.]com onesoftware[.]info serverop-parametrs[.]com web-privacy[.
domainonesoftware.infotent-protect[.]net control-issue[.]net office-confirm[.]com onesoftware[.]info serverop-parametrs[.]com web-privacy[.]net net-plugin[.]o
domainriamir.net[.]info mirconnect[.]info sber-cloud[.]info gosportal[.]net riamir[.]net web-wathapp[.]com PowerShower C2 yandisk[.]info yandeskto
domainsber-cloud.infoVBShower C2 yandesks[.]net yandisk[.]info mirconnect[.]info sber-cloud[.]info gosportal[.]net riamir[.]net web-wathapp[.]com PowerShowe
domainserverop-parametrs.comcontrol-issue[.]net office-confirm[.]com onesoftware[.]info serverop-parametrs[.]com web-privacy[.]net net-plugin[.]org triger-working[.]com V
domaintriger-working.comserverop-parametrs[.]com web-privacy[.]net net-plugin[.]org triger-working[.]com VBShower C2 yandesks[.]net yandisk[.]info mirconnect[.]in
domainweb-privacy.nete-confirm[.]com onesoftware[.]info serverop-parametrs[.]com web-privacy[.]net net-plugin[.]org triger-working[.]com VBShower C2 yandesk
domainweb-wathapp.comnnect[.]info sber-cloud[.]info gosportal[.]net riamir[.]net web-wathapp[.]com PowerShower C2 yandisk[.]info yandesktop[.]com web-wathap
domainyandesks.netacy[.]net net-plugin[.]org triger-working[.]com VBShower C2 yandesks[.]net yandisk[.]info mirconnect[.]info sber-cloud[.]info gospor
domainyandesktop.comiamir[.]net web-wathapp[.]com PowerShower C2 yandisk[.]info yandesktop[.]com web-wathapp[.]com Cloud repositories used ​by VBCloud web
domainyandisk.infolugin[.]org triger-working[.]com VBShower C2 yandesks[.]net yandisk[.]info mirconnect[.]info sber-cloud[.]info gosportal[.]net riami
md50139f32a523d453bc338a67ca45c224dC74C0BE9858853 F45008BF1889A8655D32A0EB93B8ACDD VBCloud MD5 0139F32A523D453BC338A67CA45C224D 01DB58A1D0EC85ADC13290A6290AD9D6 0F37E1298E4C82098DC9318C7E
md5016b6a035b44c1ad10d070abcdfe2f66A00 VBShower::Launcher MD5 AA8DA99D5623FAFED356A14E59ACBB90 016B6A035B44C1AD10D070ABCDFE2F66 160A65E830EB97AAE6E1305019213558 184CF8660AF7538CD1CD2559A1
md501db58a1d0ec85adc13290a6290ad9d632A0EB93B8ACDD VBCloud MD5 0139F32A523D453BC338A67CA45C224D 01DB58A1D0EC85ADC13290A6290AD9D6 0F37E1298E4C82098DC9318C7E65F9D2 6FCEE9878216019C8DFA887075
md50f37e1298e4c82098dc9318c7e65f9d22A523D453BC338A67CA45C224D 01DB58A1D0EC85ADC13290A6290AD9D6 0F37E1298E4C82098DC9318C7E65F9D2 6FCEE9878216019C8DFA887075C5E68E D445D443ACE329FB244EDC3E51
md515fd46ac775a30b1963281a037a771b1C384CA4666 A30319545FDA9E2DA0532746C09130EB PowerShower MD5 15FD46AC775A30B1963281A037A771B1 31B01387CA60A1771349653A3C6AD8CA 389BC3B9417D893F3324221141
md5160a65e830eb97aae6e13050192135589D5623FAFED356A14E59ACBB90 016B6A035B44C1AD10D070ABCDFE2F66 160A65E830EB97AAE6E1305019213558 184CF8660AF7538CD1CD2559A10B6622 1AF1F9434E4623B7046CF6360E
md5184cf8660af7538cd1cd2559a10b6622035B44C1AD10D070ABCDFE2F66 160A65E830EB97AAE6E1305019213558 184CF8660AF7538CD1CD2559A10B6622 1AF1F9434E4623B7046CF6360E0A520E 1BFB9CBA8AA23A401925D356B2
md51af1f9434e4623b7046cf6360e0a520eE830EB97AAE6E1305019213558 184CF8660AF7538CD1CD2559A10B6622 1AF1F9434E4623B7046CF6360E0A520E 1BFB9CBA8AA23A401925D356B2F6E7ED 21585D5881CC11ED1F615FDB2D
md51bfb9cba8aa23a401925d356b2f6e7ed660AF7538CD1CD2559A10B6622 1AF1F9434E4623B7046CF6360E0A520E 1BFB9CBA8AA23A401925D356B2F6E7ED 21585D5881CC11ED1F615FDB2D7ACC11 242E86E658FE6AB6E4C81B6816
md521585d5881cc11ed1f615fdb2d7acc11434E4623B7046CF6360E0A520E 1BFB9CBA8AA23A401925D356B2F6E7ED 21585D5881CC11ED1F615FDB2D7ACC11 242E86E658FE6AB6E4C81B68162B3001 2FE7E75BC599B1C68B87CF2A3E
md5242e86e658fe6ab6e4c81b68162b3001BA8AA23A401925D356B2F6E7ED 21585D5881CC11ED1F615FDB2D7ACC11 242E86E658FE6AB6E4C81B68162B3001 2FE7E75BC599B1C68B87CF2A3E7AA51F 36DD0FBD19899F0B23ADE5A1DE
md52d24044c0a5b9ebe4e01ded2bfc2b3a411CB9D1D71F0FA70ECD1AF2480 CBFB691E95EE34A324F94ED1FF91BC23 2D24044C0A5B9EBE4E01DED2BFC2B3A4 88BE01F8C4A9F335D33FA7C384CA4666 A30319545FDA9E2DA0532746C0
md52fe7e75bc599b1c68b87cf2a3e7aa51f5881CC11ED1F615FDB2D7ACC11 242E86E658FE6AB6E4C81B68162B3001 2FE7E75BC599B1C68B87CF2A3E7AA51F 36DD0FBD19899F0B23ADE5A1DE3C2FEC 389F6E6FD9DCC84C6E944DC387
md531b01387ca60a1771349653a3c6ad8ca46C09130EB PowerShower MD5 15FD46AC775A30B1963281A037A771B1 31B01387CA60A1771349653A3C6AD8CA 389BC3B9417D893F3324221141EDEA00 VBShower::Launcher MD5 AA8
md536dd0fbd19899f0b23ade5a1de3c2fecE658FE6AB6E4C81B68162B3001 2FE7E75BC599B1C68B87CF2A3E7AA51F 36DD0FBD19899F0B23ADE5A1DE3C2FEC 389F6E6FD9DCC84C6E944DC387087A56 3A54ACD967DD104522BA7D66F4
md5389bc3b9417d893f3324221141edea00AC775A30B1963281A037A771B1 31B01387CA60A1771349653A3C6AD8CA 389BC3B9417D893F3324221141EDEA00 VBShower::Launcher MD5 AA8DA99D5623FAFED356A14E59ACBB90 016
md5389f6e6fd9dcc84c6e944dc387087a565BC599B1C68B87CF2A3E7AA51F 36DD0FBD19899F0B23ADE5A1DE3C2FEC 389F6E6FD9DCC84C6E944DC387087A56 3A54ACD967DD104522BA7D66F4D86544 3F12BF4A8D82654861B5B5993C
md53a54acd967dd104522ba7d66f4d86544BD19899F0B23ADE5A1DE3C2FEC 389F6E6FD9DCC84C6E944DC387087A56 3A54ACD967DD104522BA7D66F4D86544 3F12BF4A8D82654861B5B5993C012BFA 49F8ED13A8A13799A34CC999B1
md53f12bf4a8d82654861b5b5993c012bfa6FD9DCC84C6E944DC387087A56 3A54ACD967DD104522BA7D66F4D86544 3F12BF4A8D82654861B5B5993C012BFA 49F8ED13A8A13799A34CC999B195BF16 4B96DC735B622A94D3C74C0BE9
md549f8ed13a8a13799a34cc999b195bf16D967DD104522BA7D66F4D86544 3F12BF4A8D82654861B5B5993C012BFA 49F8ED13A8A13799A34CC999B195BF16 4B96DC735B622A94D3C74C0BE9858853 F45008BF1889A8655D32A0EB93
md54b96dc735b622a94d3c74c0be98588534A8D82654861B5B5993C012BFA 49F8ED13A8A13799A34CC999B195BF16 4B96DC735B622A94D3C74C0BE9858853 F45008BF1889A8655D32A0EB93B8ACDD VBCloud MD5 0139F32A523D45
md56fcee9878216019c8dfa887075c5e68eA1D0EC85ADC13290A6290AD9D6 0F37E1298E4C82098DC9318C7E65F9D2 6FCEE9878216019C8DFA887075C5E68E D445D443ACE329FB244EDC3E5146313B F3F28018FB5108B516D802A038
md588be01f8c4a9f335d33fa7c384ca46661E95EE34A324F94ED1FF91BC23 2D24044C0A5B9EBE4E01DED2BFC2B3A4 88BE01F8C4A9F335D33FA7C384CA4666 A30319545FDA9E2DA0532746C09130EB PowerShower MD5 15FD46AC77
md59d3557cc5c444fe5d73e4c7fe1872414bdav.mydrive.ch webdav.yandex.ru kim.nl.tab.digital HTA MD5 9D3557CC5C444FE5D73E4C7FE1872414 CBA05E11CB9D1D71F0FA70ECD1AF2480 CBFB691E95EE34A324F94ED1FF
md5a30319545fda9e2da0532746c09130eb4C0A5B9EBE4E01DED2BFC2B3A4 88BE01F8C4A9F335D33FA7C384CA4666 A30319545FDA9E2DA0532746C09130EB PowerShower MD5 15FD46AC775A30B1963281A037A771B1 31B01387CA
md5aa8da99d5623fafed356a14e59acbb908CA 389BC3B9417D893F3324221141EDEA00 VBShower::Launcher MD5 AA8DA99D5623FAFED356A14E59ACBB90 016B6A035B44C1AD10D070ABCDFE2F66 160A65E830EB97AAE6E1305019
md5cba05e11cb9d1d71f0fa70ecd1af2480kim.nl.tab.digital HTA MD5 9D3557CC5C444FE5D73E4C7FE1872414 CBA05E11CB9D1D71F0FA70ECD1AF2480 CBFB691E95EE34A324F94ED1FF91BC23 2D24044C0A5B9EBE4E01DED2BF
md5cbfb691e95ee34a324f94ed1ff91bc23CC5C444FE5D73E4C7FE1872414 CBA05E11CB9D1D71F0FA70ECD1AF2480 CBFB691E95EE34A324F94ED1FF91BC23 2D24044C0A5B9EBE4E01DED2BFC2B3A4 88BE01F8C4A9F335D33FA7C384
md5d445d443ace329fb244edc3e5146313b298E4C82098DC9318C7E65F9D2 6FCEE9878216019C8DFA887075C5E68E D445D443ACE329FB244EDC3E5146313B F3F28018FB5108B516D802A038F90BDE
md5f3f28018fb5108b516d802a038f90bde878216019C8DFA887075C5E68E D445D443ACE329FB244EDC3E5146313B F3F28018FB5108B516D802A038F90BDE
md5f45008bf1889a8655d32a0eb93b8acdd13A8A13799A34CC999B195BF16 4B96DC735B622A94D3C74C0BE9858853 F45008BF1889A8655D32A0EB93B8ACDD VBCloud MD5 0139F32A523D453BC338A67CA45C224D 01DB58A1D0EC85
Full article2,691 words · extracted from securelist.com · click to collapse

Introduction

Known since 2014, Cloud Atlas targets Eastern Europe and Central Asia. We’re shedding light on a previously undocumented toolset, which the group used heavily in 2024. Victims get infected via phishing emails containing a malicious document that exploits a vulnerability in the formula editor (CVE-2018-0802) to download and execute malware code. See below for the infection pattern.

Typical Cloud Atlas infection pattern

When opened, the document downloads a malicious template formatted as an RTF file from a remote server controlled by the attackers. It contains a formula editor exploit that downloads and runs an HTML Application (HTA) file hosted on the same C2 server. The RTF and HTA downloads are restricted to certain time slots and victim IP addresses: requests are only allowed from target regions.

The malicious HTA file extracts and writes several files to disk that are parts of the VBShower backdoor. VBShower then downloads and installs another backdoor: PowerShower. This infection scheme was originally described back in 2019 and has changed only slightly from year to year.

Previously, Cloud Atlas employed PowerShower to download and run an executable file: a DLL library. This DLL would then fetch additional executable modules (plug-ins) from the C2 server and execute these in memory. Among these plug-ins was one specifically designed to exfiltrate files with extensions of interest to the attackers: DOC, DOCX, XLS, XLSX, PDF, RTF, JPG and JPEG. The plugins were downloaded and their output was uploaded via the WebDAV protocol over public cloud services. Interestingly, after a plug-in was successfully downloaded, the DLL would delete the file from the cloud.

The VBCloud backdoor now replicates the executable file’s original capabilities, such as downloading and executing malicious plug-ins, communicating with a cloud server, and performing other tasks. We first detected attacks using this implant in August of last year. Since then, we’ve observed numerous variations of the backdoor which have helped it to stay under the radar. This new campaign loads VBCloud via VBShower, which also downloads the PowerShower module. PowerShower probes the local network and facilitates further infiltration, while VBCloud collects information about the system and steals files. Below, we use a sample seen in September 2024 as a case study to examine each stage of a Cloud Atlas attack that employs the new toolkit.

Technical details

HTA

The exploit downloads the HTA file via the RTF template and runs it. It leverages the alternate data streams (NTFS ADS) feature to extract and create several files at %APPDATA%\Roaming\Microsoft\Windows\. These files make up the VBShower backdoor.

Sample HTA content

Below are the VBShower components loaded by the HTA dropper.

File name Description
AppCache028732611605321388.log:AppCache02873261160532138892.vbs VBShower Launcher (copy)
AppCache028732611605321388.log:AppCache028732611605321388.vbs VBShower Launcher
AppCache028732611605321388.log:AppCache028732611605321388.dat Encrypted VBShower backdoor
AppCache028732611605321388.log:AppCache0287326116053213889292.vbs VBShower Cleaner

After the download is complete, the malware adds a registry key to auto-run the VBShower Launcher script.

1

2

"Software\Microsoft\Windows\\CurrentVersion\Run","dmwappushservice","wscript /B "%APPDATA%\Roaming

\Microsoft\Windows\AppCache028732611605321388.log:AppCache028732611605321388.vbs"

The backdoor also launches further scripts: VBShower Launcher (copy) and VBShower Cleaner.

1

2

wscript/B"%APPDATA%\Roaming

\Microsoft\Windows\AppCache028732611605321388.log:AppCache02873261160532138892.vbs

1

2

wscript/B"%APPDATA%\Roaming

\Microsoft\Windows\AppCache028732611605321388.log:AppCache0287326116053213889292.vbs

The attackers create custom HTA files for each victim, so the names of the scripts and registry keys are mostly unique. For example, we have seen intertwine used as a name template, while the file names themselves looked as follows.

  • “intertwine.ini:intertwineing.vbs”;
  • “intertwine.ini:intertwineinit.vbs”;
  • “intertwine.ini:intertwine.vbs”;
  • “intertwine.ini:intertwine.con”.

VBShower

VBShower::Launcher

This script acts as a loader, responsible for reading and decrypting the contents of AppCache028732611605321388.log:AppCache028732611605321388.dat, before using the Execute() function to pass control to that file.

Sample VBShower Launcher content

VBShower::Cleaner

This script is designed to clear the contents of all files inside the \Local\Microsoft\Windows\Temporary Internet Files\Content.Word\ folder by opening each in write mode. While the files persist, their contents are erased. This is how the Trojan covers its tracks, removing malicious documents and templates it downloaded from the web during the attack.

The script uses the same method to erase both its own contents and the contents of the VBShower Launcher copy, which is used solely for the malware’s first run.

Sample VBShower Cleaner content

VBShower::Backdoor

The backdoor’s payload is contained encrypted within a DAT file.

Encrypted VBShower backdoor

VBShower::Launcher goes through several stages to decrypt the backdoor.

First decrypted layer of VBShower Backdoor

Fully decrypted and deobfuscated VBShower Backdoor content

The VBShower backdoor then runs in memory, subsequently performing several operations in a loop.

  • Check for the autorun registry key and restore it if missing.
  • Attempt to download additional encrypted VB scripts from the C2 server and run these. If the downloaded data is larger than 1 MB, the module saves the script to disk inside alternate data streams (NTFS ADS) and runs it with the help of the “wscript” utility. Otherwise, it runs the script in the current context.
  • If an alternate data stream contains a TMP file, the backdoor sends it to the C2 server with a POST request. The additional scripts downloaded from the C2 use the TMP file to store their output.

VBShower::Payload

We were able to detect and analyze a number of scripts downloaded and executed by the VBShower backdoor.

VBShower::Payload (1)

The first script we found does the following.

  • Gets the domain, username and computer.
  • Gets the names and values of the registry keys in the SOFTWARE\Microsoft\Windows\CurrentVersion\Run branch.
  • Gets information about the file names and sizes in the following folders:
    • %AppData%;
    • %AllUsersProfile%;
    • %AllUsersProfile%\Canon;
    • %AllUsersProfile%\Intel;
    • %AllUsersProfile%\Control;
    • %AllUsersProfile%\libs;
    • %AllUsersProfile%\Adobe;
    • %AllUsersProfile%\Yandex;
    • %AllUsersProfile%\Firefox;
    • %AllUsersProfile%\Edge;
    • %AllUsersProfile%\Chrome;
    • %AllUsersProfile%\avp.
  • Gets the names of running processes, their start dates and the commands that started them.
  • Gets a list of scheduler tasks by running cmd.exe/cschtasks/query/v/fo LIST.

All data collected this way is saved in a TMP alternate data stream and forwarded to the C2 server by the VBShower::Backdoor component.

The paths listed above (%AllUsersProfile%\<subfolder>) are used for installing the VBCloud backdoor. The steps performed by the script are most likely needed to check if the backdoor is present and installed correctly.

Decrypted and deobfuscated contents of script 1

VBShower::Payload (2)

The second script reboots the system.

Decrypted and deobfuscated contents of script 2

VBShower::Payload (3)

A further script downloads a ZIP archive, extracts it into the %TMP% directory, and collects the names and sizes of downloaded files to then send an extraction report to the C2. This is done to verify that the files were received and unpacked.

Decrypted and deobfuscated contents of script 3

VBShower::Payload (4) and (5)

VBShower downloads two similar scripts that are designed for installing the VBCloud and PowerShower backdoors. These scripts first download an archive from a hardcoded link and then unpack it into the %ALLUSERSPROFILE% folder. In the case of VBCloud, the script changes the extension of the unpacked file from TXT to VBS and creates a scheduler task to run VBCloud. In the case of PowerShower, the extension of the unpacked file is changed from TXT to PS1, whereupon the script adds the file to the \Run registry branch.

Unlike VBShower’s own scripts, downloadable scripts with a payload are present on disk as files, rather than hidden inside alternate data streams.

Besides installing backdoors, these scripts build a report that consists of the names of running processes, their start dates and the commands that started them, registry keys and values in the \Run branch, and a list of files and directories at the path where the archive was unpacked. This report is then sent to the C2 server.

Decrypted and deobfuscated contents of the scripts for downloading and installing VBCloud and PowerShower

PowerShower

PowerShower is nearly identical to VBShower in terms of functionality.

Sample PowerShower script installed with VBShower

PowerShower downloads additional PowerShell scripts from the C2 and executes these. If the downloaded data begins with the character “P”, PowerShower interprets the data as a ZIP archive, rather than a PowerShell script, and saves the archive to disk as “%TMP%\Firefox.zip”. PowerShower does not unpack the archive, serving as a downloader only.

Decoded PowerShower script

The downloaded PowerShell scripts run in memory, without being saved to disk. Most of the scripts save their output to sapp.xtx, which PowerShower then sends as a report to the C2.

The PowerShower scripts use the same C2 domains as VBShower.

PowerShower::Payload (1)

The script gets a list of local groups and their members on remote computers via Active Directory Service Interfaces (ADSI). The script is most often used on domain controllers.

Sample script to get a local groups and members list, downloaded and executed by PowerShower

PowerShower::Payload (2)

Script for dictionary attacks on user accounts.

Sample password bruteforcing script, downloaded and executed by PowerShower

PowerShower::Payload (3)

The script unpacks the Firefox.zip archive previously downloaded by the PowerShower backdoor, and executes the keb.ps1 script contained in the archive as a separate PowerShell process with a hidden window. The keb.ps1 script belongs to the popular PowerSploit framework for penetration testing and kicks off a Kerberoasting attack.

Sample script that launches a Kerberoasting attack, downloaded and executed by PowerShower

PowerShower::Payload (4)

This script gets a list of administrator groups.

Sample script to get a list of administrator groups, downloaded and executed by PowerShower

PowerShower::Payload (5)

This script gets a list of domain controllers.

Sample script to get a list of domain controllers, downloaded and executed by PowerShower

PowerShower::Payload (6)

This script gets information about files inside the ProgramData directory.

Sample script to get information about files inside the ProgramData directory, downloaded and executed by PowerShower

PowerShower::Payload (7)

This script gets the account policy and password policy settings on the local computer.

Sample script to get policy settings, downloaded and executed by PowerShower

PowerShower::Payload:: Inveigh

We also observed the use of PowerShell Inveigh, a machine-in-the-middle attack utility used in penetration testing. Inveigh is used for data packet spoofing attacks, and collecting hashes and credentials both by intercepting packets and by using protocol-specific sockets.

The Inveigh script is extracted from the ZIP archive downloaded by PowerShower and runs as described under PowerShower::Payload (3).

Sample Inveigh script, downloaded and executed by PowerShower

VBCloud

As described above, VBCloud is installed via VBShower. We found the following module installation paths.

1

2

3

4

5

6

7

8

9

C:\ProgramData\avp\avp_upd.vbs

C:\ProgramData\Adobe\AdobeLog.vbs

C:\ProgramData\Adobe\manager.vbs

C:\ProgramData\Adobe\sysman.vbs

C:\ProgramData\Adobe\news_adobe.vbs

C:\ProgramData\Adobe\upgrade.vbs

C:\ProgramData\Edge\SrvMngrUpd.vbs

C:\ProgramData\Edge\intelog.vbs

C:\ProgramData\Chrome\ChromeSys.vbs

Sample VBCloud main module paths

The core functionality of the VBCloud module duplicates that of VBShower: both download and run PowerShell scripts with a payload, and then send the output to the C2. Unlike VBShower, however, VBCloud uses public cloud storage as the C2.

Sample VBCloud script

The VBCloud script does not contain any loops, and it is designed to execute only once. However, it gets triggered by a scheduled task every time the user logs into the system, which means it will run frequently. We’ve also seen variants of the backdoor that executed their core functionality in a loop with a thirty-minute delay between repetitions. These variants ran the script once via the \Run registry branch when the system booted up for the first time after being infected.

Decrypted and deobfuscated VBCloud script

VBCloud does the following:

  • Check the availability of the kim.nl.tab.digital WebDav server by sending an HTTP MKCOL request to create the directories named “kmsobuqjquut” and “rwqdmpaohxns” with the credentials hardcoded in the script. If the server is unavailable, the script switches to the backup address “webdav.mydrive.ch”.
  • If the WebDav server is available, create a file in the “kmsobuqjquut” directory on that server via an HTTP PUT The file name follows the pattern ddmmyy_HHMMSS, and the extension is randomly selected from among TXT, RTF, DOC, PPT, MDS, PNG and JPEG. We have seen files named “070824_001919.txt” and “250724_002919.doc”. Files like these contain the username and MAC addresses of network adapters, effectively confirming that the script is active on the infected system.
  • The Trojan then attempts to download one of three files from the “rwqdmpaohxns” directory: “criclyqnduv.txt”, “jhflenoqelp.txt” or “avnwiabihik.txt”. If VBCloud successfully downloads the file, it immediately deletes it from the cloud with an HTTP DELETE request, and then executes it in the current process via the Execute() function after decrypting the contents. As in the case of PowerShower, the payload can be made up of various scripts.

VBCloud::Payload (1)

This script is designed to send information about disks to the C2.

VBCloud::Payload (2)

This script is designed to exfiltrate files and documents. It iterates through local drives and removable media in search of files with the extensions DOC, DOCX, XLS, XLSX, PDF, TXT, RTF and RAR. The script checks the size of any files it finds to match this condition and collects those between 1000 and 3,000,000 bytes to exfiltrate. The files must have been modified no more than 72 hours before the current date. The script then copies matching files to a ZIP archive it creates, named “mapping.zip”. It also adds a file with metadata such as the created time, modified time, last opened time, and full path to the file. Upon exceeding 4,000,000 bytes, an archive is uploaded to cloud storage and deleted from the system. It is replaced with a new one, and the file harvesting process continues. The archive is uploaded in RC4-encrypted form, with a name that follows the template “%d_13134” and one of the following extensions chosen at random: MP3, AAC, MP2, FLAC, WAV, ALAC, MQA, OGG, DSD, WMA, and MP4.

Part of the file exfiltration script

VBCloud::Payload (3)

This script gets various system information such as the OS version, RAM size, manufacturer, computer name, username and domain name.

VBCloud::Payload (4)

Script to exfiltrate Telegram files:

  • The file D877F783D5D3EF8Cs contains the user ID and encryption key used for interaction between the desktop client and Telegram servers.
  • The file key_datas contains local encryption keys.

Part of the file exfiltration script

Geography of attacked users

Several dozen users were attacked in 2024, 82% of these in Russia. Isolated attacks were recorded in Belarus, Canada, Moldova, Israel, Kyrgyzstan, Vietnam and Turkey.

Conclusion

We continue to monitor activity linked to Cloud Atlas. In a new campaign that began in August 2023, the attackers made changes to their familiar toolkit. This time, instead of an executable library to load malware modules, the group relied on the VBShower backdoor as the loader. Besides, they are now using a new module in their attacks: VBCloud. This collects and uploads system information and other data. These actions employ a variety of PowerShell scripts that enable the attackers to perform a range of tasks on the victim’s system. VBCloud uses public cloud storage as a C2 server.

The infection chain consists of several stages and ultimately aims to steal data from victims’ devices. We’ve observed that, similar to past Cloud Atlas campaigns, phishing emails continue to be the initial access point. This underscores the still-pressing need for organizations to strengthen their infrastructure defenses and improve employee awareness to ward off these kinds of attacks.

If you want to try analyzing the sample from earlier Cloud Atlas attacks and other infamous malware samples yourself, you can take the Advanced Malware Analysis Techniques course from Kaspersky GReAT.

Indicators of compromise

HTA file download domains
content-protect[.]net
control-issue[.]net
office-confirm[.]com
onesoftware[.]info
serverop-parametrs[.]com
web-privacy[.]net
net-plugin[.]org
triger-working[.]com

VBShower C2
yandesks[.]net
yandisk[.]info
mirconnect[.]info
sber-cloud[.]info
gosportal[.]net
riamir[.]net
web-wathapp[.]com

PowerShower C2
yandisk[.]info
yandesktop[.]com
web-wathapp[.]com

Cloud repositories used ​by VBCloud
webdav.opendrive.com
webdav.mydrive.ch
webdav.yandex.ru
kim.nl.tab.digital

HTA MD5
9D3557CC5C444FE5D73E4C7FE1872414
CBA05E11CB9D1D71F0FA70ECD1AF2480
CBFB691E95EE34A324F94ED1FF91BC23
2D24044C0A5B9EBE4E01DED2BFC2B3A4
88BE01F8C4A9F335D33FA7C384CA4666
A30319545FDA9E2DA0532746C09130EB

PowerShower MD5
15FD46AC775A30B1963281A037A771B1
31B01387CA60A1771349653A3C6AD8CA
389BC3B9417D893F3324221141EDEA00

VBShower::Launcher MD5
AA8DA99D5623FAFED356A14E59ACBB90
016B6A035B44C1AD10D070ABCDFE2F66
160A65E830EB97AAE6E1305019213558
184CF8660AF7538CD1CD2559A10B6622
1AF1F9434E4623B7046CF6360E0A520E
1BFB9CBA8AA23A401925D356B2F6E7ED
21585D5881CC11ED1F615FDB2D7ACC11
242E86E658FE6AB6E4C81B68162B3001
2FE7E75BC599B1C68B87CF2A3E7AA51F
36DD0FBD19899F0B23ADE5A1DE3C2FEC
389F6E6FD9DCC84C6E944DC387087A56
3A54ACD967DD104522BA7D66F4D86544
3F12BF4A8D82654861B5B5993C012BFA
49F8ED13A8A13799A34CC999B195BF16
4B96DC735B622A94D3C74C0BE9858853
F45008BF1889A8655D32A0EB93B8ACDD

VBCloud MD5
0139F32A523D453BC338A67CA45C224D
01DB58A1D0EC85ADC13290A6290AD9D6
0F37E1298E4C82098DC9318C7E65F9D2
6FCEE9878216019C8DFA887075C5E68E
D445D443ACE329FB244EDC3E5146313B
F3F28018FB5108B516D802A038F90BDE

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/cloud-atlas-attacks-with-new-backdoor-vbcloud/115103/