Inception
MITRE ATT&CK: G0100 View on attack.mitre.org
Aliases: Inception Framework, Cloud Atlas, Clean Ursa, OXYGEN, ATK116, Blue Odin, Inception
- First seen
- 2014-01-01 00:00:00
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 14 (1 malicious)
- Last IoC activity
- 2026-07-31 21:23:44
- Profile updated
- 2026-07-07 11:48:07
Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities defense-and-aerospace
Targeted regions: country_code:ru country_code:us country_code:de country_code:fr country_code:gb country_code:cn
Context
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Inception (G0100). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 21b7ab52098b8d3f90f6a36362cba6a68967ae318b07e3ac99757d2d21ba2479 | 2026-06-04 | 1 |
Detection coverage
- 5 YARA rules
- 475 Sigma rules
Malware & tools used
- Tool (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Web Service (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Software Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- System Information Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Malicious File (attack-pattern)
- Web Protocols (attack-pattern)
- Data from Local System (attack-pattern)
- Mshta (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Domain Groups (attack-pattern)
- Visual Basic (attack-pattern)
- Template Injection (attack-pattern)
- Regsvr32 (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Process Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- PowerShower (malware)
- VBShower (malware)
- LaZagne (malware)
Reports & references
- pwc.com — Yir Cyber Threats Report Download (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- cfr.org — Inception Framework (report)
- web.archive.org — Blue Coat Exposes %E2%80%9C Inception Framework%E2%80%9D Very Sophisticated Layered Malware (report)
- paper.seebug.org — Inception Apt Analysis Bluecoat (report)
- logrhythm.com — Catching The Inception Framework Phishing Attack (report)
- paper.seebug.org — Bcs Wp Inceptionreport En V12914 (report)
- Kaspersky — 57647 (report)
- Kaspersky — 36740 (report)
- Kaspersky — 57645 (report)
- Kaspersky — 68083 (report)
- Kaspersky — 81899 (report)
- Palo Alto Unit 42 — Unit42 Inception Attackers Target Europe Year Old Office Vulnerability (report)
- Kaspersky — 92016 (report)
- Broadcom/Symantec — Inception Framework Hiding Behind Proxies (report)
- akamai.com — Upnproxy Blackhat Proxies Via Nat Injections White Paper (report)
- pwc.com — Yir Cyber Threats Annex Download (report)
- Palo Alto Unit 42 — Clean Ursa (report)
- cfr.org — Cloud Atlas (report)
- cfr.org — Red October (report)
- MITRE ATT&CK — G0100 (report)
- Broadcom/Symantec — Inception Framework Hiding Behind Proxies (report)
External references
- mitre-attack — G0100
- Cloud Atlas
- Inception
- Inception Framework
- Kaspersky Cloud Atlas December 2014
- Unit 42 Inception November 2018
- Symantec Inception Framework March 2018
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy