Inception

MITRE ATT&CK: G0100 View on attack.mitre.org

Aliases: Inception Framework, Cloud Atlas, Clean Ursa, OXYGEN, ATK116, Blue Odin, Inception

First seen
2014-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
14 (1 malicious)
Last IoC activity
2026-07-31 21:23:44
Profile updated
2026-07-07 11:48:07

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities defense-and-aerospace

Targeted regions: country_code:ru country_code:us country_code:de country_code:fr country_code:gb country_code:cn

Context

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Inception (G0100). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 21b7ab52098b8d3f90f6a36362cba6a68967ae318b07e3ac99757d2d21ba2479 2026-06-04 1

Detection coverage

  • 5 YARA rules
  • 475 Sigma rules

Malware & tools used

  • Tool (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Web Service (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Software Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • System Information Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Malicious File (attack-pattern)
  • Web Protocols (attack-pattern)
  • Data from Local System (attack-pattern)
  • Mshta (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Domain Groups (attack-pattern)
  • Visual Basic (attack-pattern)
  • Template Injection (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Process Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • PowerShower (malware)
  • VBShower (malware)
  • LaZagne (malware)

Reports & references

  • pwc.com — Yir Cyber Threats Report Download (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • cfr.org — Inception Framework (report)
  • web.archive.org — Blue Coat Exposes %E2%80%9C Inception Framework%E2%80%9D Very Sophisticated Layered Malware (report)
  • paper.seebug.org — Inception Apt Analysis Bluecoat (report)
  • logrhythm.com — Catching The Inception Framework Phishing Attack (report)
  • paper.seebug.org — Bcs Wp Inceptionreport En V12914 (report)
  • Kaspersky — 57647 (report)
  • Kaspersky — 36740 (report)
  • Kaspersky — 57645 (report)
  • Kaspersky — 68083 (report)
  • Kaspersky — 81899 (report)
  • Palo Alto Unit 42 — Unit42 Inception Attackers Target Europe Year Old Office Vulnerability (report)
  • Kaspersky — 92016 (report)
  • Broadcom/Symantec — Inception Framework Hiding Behind Proxies (report)
  • akamai.com — Upnproxy Blackhat Proxies Via Nat Injections White Paper (report)
  • pwc.com — Yir Cyber Threats Annex Download (report)
  • Palo Alto Unit 42 — Clean Ursa (report)
  • cfr.org — Cloud Atlas (report)
  • cfr.org — Red October (report)
  • MITRE ATT&CK — G0100 (report)
  • Broadcom/Symantec — Inception Framework Hiding Behind Proxies (report)

External references