Skip to content

APT Group Patches termsrv.dll to Enable Multiple RDP Sessions

Gbhackers •Mayura Kathir • May 25, 2026

A sustained cyber espionage campaign attributed to the Cloud Atlas advanced persistent threat (APT) group has introduced a stealthy technique that modifies the Windows termsrv.dll library to enable multiple Remote Desktop Protocol (RDP) sessions on compromised systems. Observed throughout 2025 and continuing into 2026, the activity primarily targets government and commercial entities in Russia and […]

Extracted Entities

APT Groups (1)

Countries (1)

Industries (1)

MITRE ATT&CK (1)

Platforms (1)