Inception
Also reported as Inception Framework, Cloud Atlas, Blue Odin, Clean Ursa, OXYGEN and 4 other names. Linked to Russia by three sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
Show all 22 techniques Show fewer
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2009-3129 KEV
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2013-0422 KEV ransomware
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2014-1761 KEV
- CVE-2014-6332 KEV
- CVE-2015-2360 KEV
Show all 59 CVEs Show fewer
- CVE-2016-0147
- CVE-2016-1010 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-0880 KEV
- CVE-2019-11043 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21551 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-26352 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-32434 KEV
- CVE-2023-32435 KEV
- CVE-2023-36033 KEV
- CVE-2023-38606 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-41990 KEV
- CVE-2023-42793 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-30051 KEV ransomware
- CVE-2025-2783 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bankshot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
Show all 97 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Conti (Malware Family)
-
Inception Framework, Cloud Atlas - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Inception Framework, Cloud Atlas - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
APT Cloud Atlas- Unbroken Threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Cloud Atlas- Unbroken Threat
-
Cloud Atlas targets entities in Russia and Belarus amid the ongoing war in Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cloud Atlas targets entities in Russia and Belarus amid the ongoing war in Ukraine
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cloud Atlas Maldoc
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CloudFall Targets Researchers and Scientists Invited to International Military Conferences in Central Asia and Eastern Europe
-
Cloud Atlas Navigates Us Into New Waters
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cloud Atlas Navigates Us Into New Waters
-
COVID-19 Phishing With a Side of Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COVID-19 Phishing With a Side of Cobalt Strike
-
The Continuous Conundrum of Cloud Atlas
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Continuous Conundrum of Cloud Atlas
-
Current Events to Widespread Campaigns- Pivoting from Samples to Identify Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Current Events to Widespread Campaigns- Pivoting from Samples to Identify Activity
-
The original link failed its last check. Original publisher Detailsfor Group-IB%20RedCurl.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inception
-
cybersecurity-threatscape-2019-q4-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2019-q4-eng
-
Recent Cloud Atlas activity _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Recent Cloud Atlas activity _ Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Recent Cloud Atlas activity
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Recent Cloud Atlas activity
-
Inception Attackers Target Europe with Year-old Office Vulnerability
The original link failed its last check. Original publisher Detailsfor Inception Attackers Target Europe with Year-old Office Vulnerability
-
Inception Framework_ Alive and Well, and Hiding Behind Proxies _ Symantec Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Inception Framework_ Alive and Well, and Hiding Behind Proxies _ Symantec Blogs
-
Inception Framework- Alive and Well, and Hiding Behind Proxies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inception Framework- Alive and Well, and Hiding Behind Proxies
-
Bartholomew-GuerreroSaade-VB2016.indd
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bartholomew-GuerreroSaade-VB2016.indd
-
Securelist | The "Red October" Campaign - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Securelist | The "Red October" Campaign - Securelist
-
Catching the “Inception Framework” Phishing Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Catching the “Inception Framework” Phishing Attack
-
Cloud Atlas- RedOctober APT is back in style
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cloud Atlas- RedOctober APT is back in style
-
Cloud Atlas: RedOctober APT is back in style - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cloud Atlas: RedOctober APT is back in style - Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Blue Coat Exposes “The Inception Framework”; Very Sophisticated, Layered Malware Attack Targeted at Military, Diplomats, and Bus
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Blue Coat Systems, Inc
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Blue Coat Exposes “The Inception Framework”; Very Sophisticated, Layered Malware Attack Targeted at Military, Diplomats, and Business Execs
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Blue Coat Exposes “The Inception Framework”; Very Sophisticated, Layered Malware Attack Targeted at Military, Diplomats, and Business Execs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The “Red October” Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies
Newest first. Details opens the report in Explore.