Inception Framework
This threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa, Europe, and the Middle East, for the purpose of espionage.
Inception Framework is a Russian state espionage actor targeting government and energy sectors via Spearphishing and PowerShell malware.
Inception Framework (aka Clean Ursa, Cloud Atlas, OXYGEN) is a Russian nation-state espionage actor. It targets government bodies, embassies, and private-sector organizations in energy, defense, aerospace, research, and media across Africa, Europe, and the Middle East, including several post-Soviet states. The group relies on Spearphishing Attachments to deliver malware like PowerShower and VBShower, leveraging PowerShell for execution, Registry Run Keys for persistence, and Multi-hop Proxy for C2 obfuscation. Defenders should prioritize filtering suspicious email attachments, monitoring PowerShell execution logs, and detecting anomalous Mshta and Web Service traffic.
This threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa, Europe, and the Middle East, for the purpose of espionage.
Monitor for tool development to evade security products and update their signatures if possible.
Monitor email attachments and their content for suspicious spearphishing attachments.
Monitor endpoint execution events for suspicious PowerShell scripts and malicious file execution.
Detect persistence attempts by monitoring Registry Run Keys and Startup Folder modifications.
Monitor file system and process execution for suspicious encrypted files and Mshta execution.
Monitor browser and their extension activity to detect credential theft from web browsers.
Monitor file system and process execution to detect file and directory discovery and software discovery operations.
Monitor file system and process execution to detect data collection from local system.
Monitor network traffic to detect suspicious network activity, including multi-hop proxy and web service usage.
Inception Framework gains initial access via Spearphishing Attachment.
It uses Multi-hop Proxy to obfuscate C2 communication.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.