Cloud Cover: How Malicious Actors Are Leveraging Cloud Services


The number of threat actors leveraging legitimate cloud services in their attacks has grown this year as attackers have begun to realize their potential to provide low-key and low-cost infrastructure.

Traffic to and from well known, trusted services such as Microsoft OneDrive or Google Drive may be less likely to raise red flags than communications with attacker-controlled infrastructure. In the past few weeks alone, Symantec’s Threat Hunter Team has identified three further espionage operations using cloud services and found evidence of further tools in development.

Read more…
Source: Symantec


Sign up for our Newsletter


Related:

  • CISA confirms it was breached by attackers using Ivanti flaws

    March 11, 2024

    One of the organizations compromised through a recently-discovered flaw in Ivanti products was, ironically enough, the US government’s Cybersecurity and Infrastructure Security Agency (CISA). Confirmation of the breach came from CISA itself, as well as from an anonymous source “with knowledge of the situation”, with a CISA spokesperson telling The Record the organization “identified activity indicating ...

  • Duvel forced to shut breweries after cyber attack

    March 9, 2024

    Belgian brewer Duvel has insisted it will have enough beer to keep supply flowing after it was hit by a cyber attack that brought production to a standstill. The company, one of the best-known Belgian beer brands, was hit by a suspected ransomware attack on Tuesday night that shut down five of its production facilities, four ...

  • FBI Report Reveals Americans Lost Staggering $3.94 Billion to Crypto Investment Scams in 2023

    March 9, 2024

    The surge in cryptocurrency scams in 2023, as reported by the FBI, underscores the growing prevalence of digital currency in online crime. With losses reaching $3.94 billion, a 53% increase from the previous year, these scams represent a significant portion of overall investment frauds, which amounted to $4.57 billion. Cryptocurrency scams encompass a range of deceptive ...

  • Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities

    March 8, 2024

    On January 10, 2024, Ivanti published a security advisory regarding two vulnerabilities in Ivanti Connect Secure VPN. These vulnerabilities, which were exploited in the wild, are identified as CVE-2023-46805 and CVE-2023-21887. The exploitation of these vulnerabilities was quickly adopted by a number of threat actors, resulting in a broad range of malicious activities. Check Point Research ...

  • Patch now! VMWare escape flaws are so serious even end-of-life software gets a fix

    March 8, 2024

    VMWare has issued secuity fixes for its VMware ESXi, Workstation, Fusion, and Cloud Foundation products. It has even taken the unusual step of issuing updates for versions of the affected software that have reached thier end-of-life, meaning they would normally no longer be supported. This flaws affect customers who have deployed VMware Workstation, VMware Fusion, and/or ...

  • Belgium’s largest coffee roaster falls victim to cyber attack

    March 8, 2024

    Coffee Beyers from the Belgian town of Puurs-Sint-Amands has fallen victim to a cyber attack. Hackers managed to break into the company’s computer systems on Thursday. Cybercriminals are clearly targeting Belgian beverage producers this week. During the night from Tuesday to Wednesday, brewery Duvel Moortgat found traces of a break-in on its servers. Read more… Source: Techzine