CVE Tools
Back to feed
Kaspersky Securelist ·EN-US Vendor research

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

By Kaspersky··10 min read

In 2025, we observed pervasive SSH tunnel activity, which has remained active into 2026, affecting many government organizations and commercial companies in Russia and Belarus. Behind some of this activity is Cloud Atlas, a group we have known since 2014. During our investigation, we identified new tools used by this group, as well as indicators of compromise.…

Continue reading on Kaspersky Securelist