Back Recordedfuture 2025 Cloud Threat Hunting and Defense Landscape
Insikt Group has observed continued trends of growth and increased activity of threat actors leveraging and exploiting cloud infrastructure to broaden the number of victims they target and infect. Recent reporting across the observed incidents shows that cloud-focused threats are converging on a few consistent patterns, which serve as the main sections of this report:
Across cases, initial access frequently comes from vulnerable or misconfigured services exposed to the internet — including application delivery controllers, monitoring dashboards, email security gateways, and enterprise resource planning (ERP) platforms — as well as stolen or weakly governed credentials sourced from public leaks, compromised developer workstations, and socially engineered helpdesk workflows. Once inside a targeted environment, threat actors systematically pivot through hybrid identity and virtual private network (VPN) infrastructure, targeting directory-synchronized accounts, non-human and executive identities, and privileged cloud roles to gain tenant-wide administrative control.
Post-compromise activity is characterized by heavy use of built-in cloud and SaaS functionality: enumerating and exfiltrating data via native storage and backup services, destroying or encrypting cloud backups and snapshots for impact, manipulating static frontends and continuous integration/continuous deployment (CI/CD) pipelines to subvert trust in applications and repositories, and using mainstream platforms such as calendar services as covert command-and-control (C2) channels.
In comparison to its iteration , the majority of the events discussed in this report indicate that threat actors are engaging in similar threat behaviors; however, there are three specific trends that appear to have emerged since the most recent iteration:
The trends associated with abuse indicate a shift in threat actor perception, demonstrating that threat actors are exploring the broader benefits that compromised cloud services can provide.
The rapid adoption and continuous evolution of cloud services have created a distinct and expanding attack space threat actors actively exploit. As organizations continue to move core systems and sensitive data from traditionally isolated, on-premises environments into internet-accessible cloud platforms, adversaries treat these deployments as a centralized collection of valuable data and often-weak security controls. They take advantage of widespread misconfigurations, uneven cloud security expertise, and the uniformity of major cloud and SaaS platforms, using publicly available discovery tools to scan at scale for exposed assets and insecure settings. At the same time, threat actors increasingly leverage cloud infrastructure for their own operations, using commercial services to host malware, maintain command-and-control, and stage data exfiltration. The same flexibility, reach, and obscured attribution that cloud services provide to legitimate users enables threat actors to blend malicious traffic with legitimate activity.
Defenders, meanwhile, operate in an environment where cloud computing is mature in terms of adoption, but still early in its practical use and secure implementation. Security teams must contend with rapidly changing product offerings, constant feature updates, and complex, distributed architectures that make it difficult to maintain complete visibility and consistent controls across regions, tenants, and services. Many organizations adopt cloud technologies with limited in-house expertise, unrealistic expectations, or suboptimal implementations, and they frequently report shortages of senior personnel capable of securely architecting and managing these environments. Skill and knowledge gaps, combined with the scale and constant change of cloud environments, result in configuration drift, unmonitored assets, and security blind spots. As a result, defenders face a growing burden: protecting highly available, globally distributed systems that deliver business value but simultaneously increase the organization’s attack surface and the likelihood of successful compromise.
This report identifies five main threats to cloud environments, each of which is explored in its respective section:
Each section includes radar charts that measure the following attributes associated with a given threat. These determinations were made by Insikt Group by investigating instances where a threat vector was observed to answer the following questions:
Figure 1 illustrates and compares attributes associated with cloud abuse. A description of each attribute can be found in the Methodology section of this report.
Cost of Impact: 3 (Moderate)
As previously determined by Insikt Group: “Successful exploitation of cloud infrastructure or the technologies embedded in it may result in multiple benefits to a threat actor, but may not directly translate to victim cost.” This determination can also be applied to the risks posed by misconfigured cloud infrastructure, as discussed in this report. In both instances, while exploitation and misconfiguration often allow threat actors to gain initial access, additional internal access, or increased permissions within a cloud environment, the overall impact on a cloud environment is not explicitly tied to exploitability or a threat actor’s ability to exploit misconfigurations.
Commonality: 5 (Very High)
Misconfigurations are a common risk in cloud environments, and threat research has consistently shown that they are frequently exploited by threat actors as an initial access vector. While not as commonly exploited for initial access, cloud environments inherit a myriad of vulnerability-related risks from third-party technologies often embedded within them.
Insikt Group additionally notes that multiple critical vulnerabilities were identified in cloud-native services within the past year; however, based on Insikt Group’s research, these vulnerabilities are discovered and disclosed much less often than vulnerabilities in the technologies embedded in cloud infrastructure.
Evolution Potential: 3 (Moderate)
The risk presented by misconfigurations and vulnerability exploitation in cloud environments is bounded by the technologies and services implemented within it. As new technologies and services become available and existing ones undergo updates, new misconfiguration and exploitation risks may arise. At the same time, threat actors can only capitalize on these risks in the context of the vulnerable or misconfigured technology or service, limiting the overall evolution potential of this risk.
Effort to Perform: 2 (Low)
Identifying known misconfigurations and vulnerabilities externally is a straightforward process for threat actors. Numerous tools exist that allow threat actors to programmatically identify and, in some cases, automatically exploit these weaknesses. Vulnerability research is much more challenging than abusing and weaponizing open-source proof-of-concept (PoC) exploits; however, based on data collected by Recorded Future, scanning and exploitation attempts indicate that vulnerability and reconnaissance activity following a vulnerability disclosure is a significantly more likely threat to defenders in terms of volume.
Data collected over the past year indicates that cloud misconfiguration and vulnerability exploitation continue to pose a critical risk to defenders, alongside common attack vectors that threat actors will exploit both within and outside cloud environments. These weaknesses enable threat actors to gain access and establish false legitimacy in cloud environments, serving as a means to achieve their ultimate goals as they continually target the environment.
Misconfiguration is an issue that cloud providers, architects, and security experts continuously attempt to mitigate in cloud environments; however, this cycle of human misconfiguration remediation can also present misconfigurations. The human, operational, and financial costs associated with monitoring, identifying, and mitigating misconfigurations in cloud environments are high. Additionally, as cloud computing continues to grow, cloud-native service offerings and the infrastructure itself also continue to grow, leading to mitigation challenges created by an increased external attack surface. Defenders must remain aware of new iterations of cloud services to ensure that configuration best practices are followed.
Exploitation in cloud environments is not as commonly identified as instances of misconfigurations due to the managed nature of cloud service providers. However, threat reporting throughout the year demonstrates that exploitation occurs both within and at the perimeter of cloud environments.
Threat actors are expected to continue focusing on cloud environments as attractive targets, leveraging a combination of configuration weaknesses and the exploitation of vulnerable public-facing technologies, particularly in the wake of high-profile vulnerability disclosures.
Based on current trends, exposure-driven risks, including configuration-related issues and unpatched or newly disclosed vulnerabilities, are likely to remain a consistent factor in cloud compromises, often enabling initial access while also impacting internal cloud services and supporting infrastructure.
As cloud adoption continues to accelerate, the volume and diversity of deployed services and technologies will also grow. This expansion increases the likelihood of both exploitable vulnerabilities and unintended exposures, reinforcing the importance of scalable security controls, timely patching, and continuous visibility across cloud environments.
Figure 2 illustrates a hypothetical attack chain involving misconfiguration and exploitation methods. Throughout this visual, Insikt Group has identified parts of the attack chain where defenders can most efficiently hunt for and mitigate behaviors associated with cloud misconfiguration and exploitation.
① Exploit Attempts Targeting Public-Facing Cloud Services and Appliances
Unpatched or misconfigured internet-exposed services, such as application gateways, VPN portals, and web applications, are frequent targets for initial access. Successful exploitation can grant remote code execution, credential theft, and a foothold for lateral movement into cloud and on-premise resources.
Defenders can mitigate these threats in the following ways:
② Script-Based Post-Compromise Activity
After gaining a foothold, threat actors often rely on script-based execution, such as PowerShell and other interpreters, with obfuscation and in-memory techniques to download tools, disable defenses, and move laterally while avoiding obvious file-based indicators.
Defenders can mitigate these threats in the following ways:
③ Unauthorized Remote Access Tools or Anomalous Binary Execution
Threat actors frequently deploy or repurpose remote access and management tools, as well as renamed or portable binaries, to maintain persistent and interactive access. These binaries often masquerade as legitimate activity and may use scheduled tasks or services for durability.
Defenders can mitigate these threats in the following ways:
④ Privilege Escalation through Identity Federation or Credential Manipulation
Cloud-focused campaigns increasingly abuse identity and federation mechanisms to escalate privileges and maintain long-lived access. By altering federation settings, abusing sync accounts, forging tokens, or creating backdoor identities, attackers can impersonate users, bypass certain multi-factor authentication (MFA) protections, and persist even after password changes.
Defenders can mitigate these threats in the following ways:
Insikt Group curated a list of events published within the past year that demonstrate the threats posed by exploitation and misconfiguration. These events are discussed below.
On October 24, 2025, Palo Alto Networks’s Unit 42 published a report detailing how threat actors abuse AzureHound in Microsoft Azure environments. AzureHound is an open-source data collection tool initially developed by SpecterOps (@SpecterOps) for penetration testing within the BloodHound suite. Per Unit 42, threat actors, specifically the Iranian-linked group Curious Serpens, the suspected state- threat actor Void Blizzard, and the ransomware operator Storm-0501, repurpose AzureHound in post-compromise discovery phases to map Microsoft Entra ID (formerly Azure Active Directory) environments. These operations targeted Azure tenants across hybrid and multi-tenant environments as recently as August 2025, enabling threat actors to perform comprehensive discovery that facilitated lateral movement and privilege escalation.
Based on Unit 42’s analysis, the infection chain begins when threat actors gain initial access to a target’s Azure environment using stolen credentials or authentication tokens. Threat actors then use information-stealing malware, such as Raccoon Stealer and Redline, to acquire credentials and session tokens from the victim’s browser. Using these stolen authentication artifacts, including usernames and passwords, refresh tokens, or JSON Web Tokens (JWTs), threat actors authenticate to the Azure environment. In some cases, they use multi-factor authentication (MFA) fatigue techniques to authenticate into the victim’s Microsoft Entra ID environment. Once authenticated, threat actors use available tokens or service principal credentials to connect to Azure APIs.
After establishing access, threat actors deploy AzureHound to implement the following features and actions:
On October 20, 2025, cybersecurity firm Darktrace published a technical blog detailing a campaign against a European telecommunications organization. According to Darktrace, the campaign, which began in early July 2025, exploited a public-facing Citrix NetScaler Gateway appliance, likely CVE-2023-3519, for initial access and deployed SnappyBee (also known as Deed RAT), a variant of ShadowPad. CVE-2023-3519 is a critical remote code execution (RCE) vulnerability in Citrix Application Delivery Controller (ADC) and Citrix Gateway appliances. Darktrace attributes the campaign to the state- threat actor Salt Typhoon with moderate confidence.
After gaining access, the threat actor pivoted from the compromised NetScaler Gateway to internal Citrix Virtual Delivery Agent (VDA) hosts within the organization's Machine Creation Services (MCS) subnet. To obscure their infrastructure and complicate attribution, the threat actor routed their initial access through an endpoint associated with the SoftEther virtual private network (VPN) service. Once inside the network, the threat actor deployed SnappyBee as a dynamic-link library (DLL) file to multiple internal Citrix VDA hosts, bundled alongside legitimate antivirus (AV) executables, such as Norton, Bkav, and IObit Malware Fighter, and executed it using DLL sideloading.
On May 28, 2025, Oasis Security published a technical blog detailing a flaw in Microsoft’s OneDrive File Picker. File Picker is a web component that allows applications to access, upload, and download files from a user’s OneDrive storage via OAuth authorization. File Picker (versions 6.0 to 7.2 using Implicit Flow and 8.0 using Microsoft Authentication Library) always requests the broad scopes Files.Read.All , Files.ReadWrite.All , and offline_access . As a result, even single-file upload consent silently grants apps full, persistent read and write access to the user’s entire OneDrive.
According to Oasis Security, web applications such as ChatGPT, Slack, Trello, ClickUp, and others that support OneDrive file uploads may unintentionally receive full read access to a user’s entire OneDrive account, even if a single file gets uploaded. Given the integration of OneDrive File Picker in numerous and diverse SaaS applications, the flaw is both widespread and trivially exploitable: a malicious app only needs to host the picker and then read the user's authorization token from localStorage or sessionStorage to enumerate or exfiltrate all files stored in the user's OneDrive account.
Oasis reported the flaw to Microsoft, which then notified vendors implementing OneDrive File Picker. At the time of writing, Microsoft has not yet issued a fix; however, per Oasis, Microsoft stated they are “considering future improvements, including more precise alignment between what OneDrive File Picker does and the access it requires.”
The flaw stems from the File Picker’s lack of fine-grained OAuth scopes. When a user authorizes a web application like ChatGPT or Slack to upload a file via OneDrive, the File Picker requests full read (and in some cases write) access to the entire OneDrive directory. This is due to the overly broad predefined scope permissions available in Microsoft Graph that cannot be customized for single-file access scenarios. Therefore, instead of exclusively granting access to a specific file, the OAuth tokens issued through the File Picker grant access beyond the selected file, extending to the user’s entire OneDrive directory. These tokens often request the offline_access scope, allowing applications to retain access for extended periods beyond the user's session.
This design flaw increases the risk due to ambiguous consent prompts that suggest access remains limited to selected files; however, in reality, applications gain permissions without clear user awareness. In File Picker version 7.0, it requests both read and write permissions even in upload scenarios, and while version 8.0 delegates authentication to developers, it does not enforce narrower scopes. As a result, users may unknowingly expose sensitive data to third-party applications with far broader access than intended.
The second flaw stems from the insecure storage of sensitive authentication tokens, such as access and refresh tokens, particularly in older versions of the File Picker (6.0 to 7.2). These versions use the “Implicit Flow” authorization method, which exposes access tokens via URL fragments and stores them as plaintext in the browser’s localStorage , allowing malicious scripts or browser extensions to access them easily. In newer versions like 8.0, with authentication handled through Microsoft Authentication Library (MSAL), developers often store tokens in sessionStorage without encryption or safeguards, leading to significant security risks. These insecure storage practices allow threat actors with access to the browser context to easily hijack tokens and gain full read access to the OneDrive account.
Based on reporting associated with the flaw, threat actors could exploit this flaw in at least two ways:
In either exploit scenario, minimal user interaction is required. Given the widespread adoption of the OneDrive File Picker across numerous collaboration and productivity platforms, the flaw is common, as any web app that embeds the OneDrive File Picker in upload mode is impacted.
On February 12, 2025, Datadog Security Labs published a write-up detailing the "WhoAMI" attack, which targets a name confusion vulnerability affecting Amazon Machine Images (AMIs) used in Amazon Web Services (AWS) environments. AMI is a pre-configured virtual machine template used to launch Elastic Compute Cloud (EC2) instances in AWS, containing the operating system, applications, and necessary configurations. EC2 is a scalable cloud computing service that provides virtual servers (instances) to run applications on AWS. According to Datadog Security Labs, which discovered the vulnerability in August 2024, threat actors can inject malicious AMIs into unsuspecting AWS accounts. Using the WhoAMI attack, threat actors can compromise a significant number of AWS environments, including those of major organizations. Notably, AWS itself had non-production systems vulnerable to this issue before implementing fixes. To mitigate this risk, AWS introduced the “Allowed AMIs” feature that allows users to restrict AMI selection to verified providers.
The vulnerability stems from improper filtering of AMI searches using the ec2:DescribeImages API. Many organizations and Infrastructure-as-Code (IaC) tools, such as Terraform, dynamically for the latest AMI matching a given name pattern. If the query omits the "owners" attribute, AWS returns a list of AMIs from trusted and untrusted sources. Threat actors can exploit this design flaw by publishing a malicious AMI with a name that mimics an official one with a more recent timestamp, causing automated processes to select it. When used to launch EC2 instances, these malicious AMIs grant threat actors control over the victim’s cloud environment, potentially leading to unauthorized access, data theft, or further network compromise. According to Datadog, the flaw is not limited to Terraform; it also affects AWS command-line interface (CLI) commands and various programming languages, including Python, Go, and Bash scripts.
DataDog shared the following exploitation steps to execute arbitrary code within a victim’s AWS environment and gain unauthorized access to cloud resources:
On February 13, 2025, Datadog released whoAMI-scanner, an open-source tool designed to identify and flag instances using untrusted AMIs. Based on the repository, whoAMI-scanner requires an AWS profile to scan, a region, and a list of trusted AMI provider accounts. If no parameters are provided, it defaults to predefined settings. Once provided, whoAMI-scanner loads the AWS configuration, retrieves the caller's AWS account identity, and determines which AWS regions to scan. For each region, it queries running EC2 instances and extracts the AMI ID associated with each instance. whoAMI-scanner then checks these AMIs against a database of known AWS accounts, categorizing them as verified, self-hosted, allowed (if AWS's "Allowed AMIs" feature is enabled), or unverified. If whoAMI-scanner finds a public AMI from an unknown or untrusted source, it flags the AMI as potentially malicious. whoAMI-scanner generates a summary report displaying the status of all analyzed AMIs and warns users unverified instances. If specified, whoAMI-scanner also writes to a CSV file. Finally, whoAMI-scanner informs operators the status of AWS’s "Allowed AMIs" feature and recommends ways to secure their environments.
On October 2, 2025, GreyNoise published a report on a coordinated one-day surge of exploitation attempts against Grafana instances vulnerable to CVE-2021-43798, a path traversal flaw that enables arbitrary file reads on exposed systems. The activity, observed on September 28, 2025, involved 110 malicious IP addresses focusing on internet-accessible Grafana deployments in the United States, Slovakia, and Taiwan, highlighting how long-patched but widely deployed software in cloud and hybrid environments remains a high-value reconnaissance and initial access vector.
The attack chain centers on HTTP requests that exploit the CVE-2021-43798 path traversal vulnerability to read arbitrary files from Grafana servers. These servers, when internet-exposed, commonly reside on cloud infrastructure or act as monitoring frontends into cloud workloads. Successful exploitation can expose sensitive configuration or credential material, enabling follow-on actions such as service discovery, lateral movement into underlying cloud resources, or pivoting to other managed services. GreyNoise notes that Grafana vulnerabilities, including CVE-2021-43798, frequently appear in reconnaissance phases of multi-step exploit chains and large-scale server-side request forgery (SSRF) and exploit waves spanning diverse software ecosystems, underscoring their role as reusable building blocks in cloud-focused toolchains rather than isolated bugs.
The observed surge exhibited tightly aligned targeting and tooling: traffic from multiple countries followed a consistent destination ratio (roughly 3:1:1 across the US, Slovakia, and Taiwan), with converging Transmission Control Protocol (TCP) and HTTP fingerprints indicating that different infrastructure sets, mainly originating from Bangladesh, with smaller clusters in China and Germany, were likely executing shared tasking or reusing a standard exploit kit and target list. In a cloud context, this pattern reflects how adversaries operationalize “resurgent” vulnerabilities. Attackers will integrate older vulnerabilities, such as CVE-2021-43798, and newer Grafana flaws into automated scanner and exploit frameworks to continuously scan large swaths of public cloud address spaces for unpatched instances. They will then selectively escalate from arbitrary file read to broader compromise when high-value telemetry or credentials are discovered.
Between February 26 and 27, 2025, Reuters and Recorded Future News reported that Belgium’s state security service (VSSE) was allegedly compromised by China-linked hackers via Barracuda Networks’s Email Security Gateway (ESG) appliance, prompting a federal judicial investigation and the agency’s decision to stop using Barracuda services. This activity is linked to earlier campaigns in which the China-nexus group UNC4841 exploited Barracuda ESG zero-day vulnerabilities to conduct long-term espionage against government and other high-value targets.
The primary exploitation path used malicious email attachments to trigger remote command injection in the ESG attachment-scanning component (CVE-2023-2868) on affected on-premise ESG versions. Crafted .tar archives abused Perl’s qx operator to execute arbitrary system commands on the gateway, which sits in front of mail servers and provides a privileged vantage point into email flows. UNC4841 then deployed custom malware, including SALTWATER (a trojanized Simple Mail Transfer Protocol [SMTP] module enabling command execution and tunneling), SEASPY (a backdoor masquerading as BarracudaMailService triggered by “magic packets”), and SEASIDE (a Lua module that turns SMTP HELO/EHLO data into reverse shells), to turn ESGs into persistent access and exfiltration nodes. Barracuda later disclosed follow-on exploitation of CVE-2023-7102 in the Spreadsheet::ParseExcel library, again via malicious Excel attachments, to reinstall updated SEASPY and SALTWATER variants after initial remediation.
Belgian reporting indicates that between 2021 and 2023, this Barracuda-focused attack chain enabled exfiltration of roughly 10% of VSSE’s email traffic via an external mail server used for communication with ministries, police, prosecutors, and foreign partners. Although the VSSE’s classified internal systems were reportedly not compromised, the same external server handled HR-related correspondence, exposing personal data for nearly half of VSSE’s staff and applicants and forcing identity document renewals for affected personnel. The case illustrates how the compromise of a single email security gateway product, through the iterative exploitation of Barracuda ESG parsing vulnerabilities and the deployment of bespoke implants, directly translated into strategic intelligence collection and the exposure of sensitive personnel data for a European intelligence service.
Cost of Impact: 4 (High)
Cloud abuse, particularly the abuse of compromised cloud assets, can incur high monetary, operational, and reputational costs for cloud tenants. Evidenced by reports throughout the past year, which are presented later in this section, threat actors often exploit compromised cloud infrastructure to maintain legitimacy within a victim's environment and perform costly operations, for which the tenant is held responsible. Additionally, in instances where threat actors register managed cloud services and abuse them in malicious activities, the providers may assume adverse impacts on their reputation.
Commonality: 4 (High)
Cloud abuse is a broad threat that originates from both compromised legitimate infrastructure and infrastructure controlled by threat actors. Based on the evidence presented in this report, threat actors are identifying and developing new methods to exploit legitimate cloud services for activities such as malware hosting, C2 hosting, and data exfiltration.
Evolution Potential: 5 (Severe)
Cloud abuse events reported within the past year demonstrate that threat actors are increasingly abusing cloud services as part of their C2 infrastructure and to host and deliver malicious payloads. The methods threat actors employ to perform these actions have also evolved, demonstrating that threat actors are actively identifying new ways to abuse cloud services.
Effort to Perform: 1 (Minimal)
Threat actors can easily register legitimate cloud services, which can then be abused for malicious purposes. Many cloud service providers require only an email address and a payment method to register for their services. Additionally, compromised victim cloud infrastructure can be easily abused by a threat actor as a result of broader cloud environment compromise.
Cloud abuse refers to the use of legitimate cloud services and infrastructure by a threat actor to perform malicious actions. This threat can generally be categorized into two main groups of activity: the abuse of threat actor-controlled cloud assets and the abuse of compromised victim cloud assets.
Within the past year, Insikt Group has noted that the abuse of compromised victim cloud assets is more prominently reported, with reporting, discussed further in the Examples in the Wild section, demonstrating that threat actors will commonly enroll in cloud services or develop cloud infrastructure with malicious intentions (mainly hosting malware, phishing websites or websites embedded with malicious artifacts, or C2 infrastructure, or deriving capabilities from cloud services, such as LLM services).
Insikt Group notes that, in contrast to iterations of this report, there has been little publicly accessible evidence within the past year, indicating either an uptick or persistence of common compromised victim cloud abuse behaviors, such as cryptojacking and business email compromise (BEC), among others.
Threat actors will likely continue to register and abuse cloud services and infrastructure to perform malicious actions.
As discussed earlier in this section, threat actors continue to identify new products and methods for abuse, demonstrating both their creativity in achieving malicious goals and the various cloud products they can procure and exploit to accomplish these goals. Threat actors recognize the anonymity these products provide, compared to similar traditional solutions, which make malicious traffic appear benign to most security products.
Threat actors will likely continue to abuse compromised cloud services during an attack chain rather than compute services that enable customized code execution, as abusing compromised victim cloud services can be financially lucrative or a means for threat actors to propagate during an attack. Additionally, over the past year, threat actors have demonstrated an interest in targeting cloud-based LLMs for abuse. This behavior is indicative of an evolution for both threat actor TTPs and victimology and signals that other service types may also be targeted in the future. It further indicates that threat actors prefer to abuse cloud resources rather than execute custom code in cloud environments to achieve malicious goals.
Because there are two distinct domains associated with cloud abuse, they are discussed separately below. Figure 4 demonstrates a hypothetical attack chain associated with threat actor-registered cloud abuse, while Figure 5 demonstrates a hypothetical attack chain associated with threat actor abuse of compromised victim cloud services. Throughout these visuals, Insikt Group has identified parts of the attack chain where defenders can most efficiently hunt for and mitigate behaviors associated with both domains of cloud abuse.
① Cloud Infrastructure Abused for Malware Hosting Threat actors will host malicious assets and tools within their own cloud infrastructure, allowing them to be loaded into victim environments during an attack. While these assets may not always be directly identifiable at the perimeter of a threat actor’s infrastructure, some threat actors may expose web servers or file systems that contain the malicious assets, allowing them to be programmatically accessed.
Defenders can mitigate these threats in the following ways:
② Exfiltration to Attacker-Controlled Cloud Locations Over the past year, threat actors have consistently demonstrated the use of cloud services and infrastructure as targets for exfiltration during attacks. Similar to the threat discussed above, threat actors use these services for exfiltration because the traffic generated during exfiltration appears benign and can, therefore, blend into common network traffic patterns.
Although this exfiltration technique poses detection and mitigation issues due to the benign nature of this traffic, there are methods for detecting and mitigating this threat, which are included below:
In instances where threat actors are exfiltrating data from a cloud environment, they have been known to exploit cloud service functions to establish exfiltration channels rather than use traditional methods of exfiltration. To detect and mitigate this threat, the following actions may be taken:
① Cloud Service Abuse
Threat actors may abuse cloud services to perform resource-intensive operations without incurring the associated costs and to make malicious operations more difficult to attribute to themselves. Ways of detecting and mitigating these threats are discussed below:
② Abuse for On-Premises Pivot
Threat actors will exploit compromised cloud services to pivot into on-premises workstations and infrastructure, often by masquerading as legitimate cloud users or services, or by leveraging existing connections between the cloud environment and these assets. Methods to detect and mitigate this threat include the following:
③ Abuse for External Propagation
Similar to the above, threat actors will also attempt to abuse cloud services to infect additional targets while masquerading as a member of the organization that owns a victimized cloud environment. Ways that this behavior can be detected and mitigated are discussed below:
Insikt Group curated a list of events published within the past year that demonstrate the threats posed by cloud abuse. These events are discussed below.
On July 10, 2025, CERT-UA reported that the Russian state- threat group APT28 (also known as UAC-0001) had conducted spearphishing attacks against Ukrainian government agencies and entities in the defense and security sectors. The campaign involved the deployment of a new Python-based infostealer dubbed LameHug, representing the first publicly documented case of malware integrating an LLM to dynamically generate commands during runtime.
The campaign began with emails impersonating a government ministry and delivering ZIP archives named Appendix.pdf.zip or Dodatok.pdf.zip . These contained .pif executables disguised as PDFs, packed with PyInstaller to execute LameHug in memory. The malware used a hijacked email account (boroda70@meta[.]ua ) to deliver payloads and leveraged compromised infrastructure, including the domain stayathomeclasses[.]com and IP address 144[.]126[.]202[.]227 , for C2 and exfiltration activities.
LameHug accessed Alibaba Cloud's Qwen 2.5-Coder-32B-Instruct LLM via Hugging Face API to generate system commands based on Base64-encoded prompts. This allowed it to evade static detection signatures and tailor its execution to victim environments in real time. Commands generated by the LLM performed reconnaissance using native Windows utilities, including systeminfo , wmic , tasklist , ipconfig , and dsquery . The collected data was stored locally at %PROGRAMDATA%\info\info.txt , and document files from user directories were staged for exfiltration.
The two LameHug variants used different exfiltration methods: one sent data via HTTP POST to a compromised website, while the other leveraged Secure File Transfer Protocol (SFTP) with hard-coded credentials. Both methods exfiltrated sensitive files like Office documents and system reconnaissance outputs. Notably, the malware did not establish persistence, aligning with “smash-and-grab” tactics focused on short-lived espionage operations.
On February 24, 2025, cybersecurity firm Kaspersky published a report detailing Operation SalmonSlalom, a multi-stage campaign that delivers the FatalRAT backdoor to industrial organizations in the APAC region. The operation primarily targets Chinese-speaking users in the manufacturing, telecommunications, and energy sectors across Taiwan, Malaysia, China, Japan, the Philippines, and other countries in the Asia-Pacific region. The threat actors heavily rely on legitimate cloud services, specifically Youdao Cloud Notes and Tencent’s MyQcloud content delivery network (CDN)/object storage, to host configuration data and payloads, enabling them to rotate their infrastructure and rapidly blend into regular traffic.
The attack chain begins with phishing emails and WeChat or Telegram messages that deliver ZIP archives masquerading as tax documents to employees at targeted industrial organizations. These archives contain a packed first-stage loader (using packers such as UPX, AsProtect, or NSPack) that contacts Youdao Cloud Notes to obtain an updated list of URLs hosting the second-stage components, Before.dll (configurator) and Fangao.dll (loader). Before.dll fetches additional configuration from Youdao-hosted notes, including C2 and payload URLs, writes this data to a local configuration file, and sends basic system profiling data to the C2. Fangao.dll then reads this configuration, performs environment checks (it looks for system language and file paths, and ensures the time zone is set to “UTC+8”) to ensure it is running on a victim system. If successful, it downloads and decrypts FatalRAT.
From there, the campaign uses a mix of GUI-driven Group Policy abuse and DLL sideloading to establish persistence and deliver FatalRAT from cloud infrastructure. Fangao.dll automates the Windows Group Policy Editor to add a logon script that launches a trojanized media player binary, thereby avoiding direct registry modification and reducing detection. It then leverages a legitimate driver utility (DriverAssistant) for DLL sideloading, placing a malicious loader DLL that contacts MyQcloud-hosted content to download FatalRAT. Once active, FatalRAT conducts reconnaissance, anti-VM checks, and establishes its own persistence, then supports keylogging, file exfiltration, command execution, Server Message Block (SMB) brute forcing for lateral movement, optional destructive actions (such as MBR overwrites), and deployment of remote access tools like UltraViewer and AnyDesk to extend interactive control over compromised industrial networks.
On May 29, 2025, Insikt Group published a Validated Intelligence Event (VIE) summarizing Google Threat Intelligence Group’s (GTIG) analysis of a cyber-espionage campaign conducted by APT41, a Chinese state- threat actor. According to GTIG, the campaign, first observed in October 2024, uses a multi-stage malware framework called TOUGHPROGRESS that exploits Google Calendar as a covert channel for C2. The campaign targets global government organizations through a phishing scheme that uses a compromised government website.
Based on Mandiant’s analysis, APT41 sends spearphishing emails containing a link to a ZIP archive named 出境海關申報清單.zip , hosted on a compromised government website. This archive includes a shortcut file (LNK) named 申報物品清單.pdf.lnk . It is disguised as a PDF using the double-file extension technique, along with a directory hosting seven image files. Among those seemingly benign image files, 6.jpg contains an encrypted payload, and 7.jpg is a DLL that decrypts and launches the payload. When a victim opens the LNK file, it executes the DLL, deletes itself to avoid detection, and opens a decoy PDF resembling a customs declaration document to divert suspicion.
The decrypted payload initiates the following three-stage execution process:
Once activated on a compromised system, TOUGHPROGRESS establishes threat actor-controlled C2 communication using Google Calendar. It creates zero-duration calendar events to exfiltrate data and polls the calendar for encrypted threat actor commands scheduled on July 30 and 31, 2023. TOUGHPROGRESS decrypts these commands using a two-layer XOR scheme that combines a static ten-byte key with a dynamic four-byte key generated for each message. After executing the commands, TOUGHPROGRESS encrypts the results and uploads them to new calendar events, establishing full-duplex communication over a legitimate platform.
According to the report, Mandiant and GTIG disrupted APT41’s infrastructure by revoking access to the malicious Workspace projects and blocking associated URLs, such as word[.]msapp[.]workers[.]dev , resource[.]infinityfreeapp[.]com , and hxxps://my5353[.]com/nWyTf , through Google Safe Browsing.
On March 1, 2025, Trend Micro Research reported a surge in activity related to ACR Stealer, accompanied by a new TTP update. ACR Stealer is a malware-as-a-service (MaaS) information stealer operated by a threat actor named “SheldIO”. According to Trend Micro Research, ACR Stealer uses advanced dead-drop resolvers to conceal its C2 infrastructure by leveraging legitimate platforms, such as Steam and Google Docs. Additionally, Trend Micro Research reported active infection in multiple countries, including the United States, Canada, Germany, France, the Czech Republic (Czechia), Brazil, Peru, Sweden, Finland, and Indonesia over the past 30 days.
Based on Trend Micro Research’s analysis, threat actors distribute ACR Stealer through cracked software downloads and use Cloudflare Web Application Firewall (WAF) to protect their distribution domains from detection. Once executed, ACR Stealer performs the following actions on a victim’s machine:
On February 27, 2025, Trend Micro published a report describing a multi-stage machine learning supply-chain attack that abuses cloud-based AI services, specifically Amazon SageMaker and Amazon Bedrock, to compromise LLM-driven applications. The source highlights that misconfigurations, over-privileged roles, and unvetted third-party ML components enable an attacker to move from a single exposed SageMaker notebook in a development account to complete control over Bedrock-based LLM workflows, guardrails, and retrieval-augmented generation (RAG)-backed knowledge bases in production.
The attack begins in the developer AWS account, where a SageMaker notebook instance with direct internet access and a default execution role is used by developers to install third-party extensions. The attacker publishes a malicious Python package that a developer installs and runs within that notebook, thereby opening a reverse shell to the attacker and granting them command execution on the ML workstation. From there, the attacker enumerates SageMaker and IAM resources via AWS CLI, discovers that the notebook’s role has powerful SageMaker and iam:PassRole permissions, and uses sagemaker:CreateNotebookInstance plus sagemaker:CreatePresignedNotebookInstanceUrl to create a new notebook bound to an administrative role. With this privilege escalation, the attacker gains effective control of the developer account and leverages CloudTrail logs to identify and assume a cross-account Bedrock role in the production account via sts:AssumeRole , bridging directly into the LLM-serving environment.
Once in the production account, the attacker abuses Bedrock Guardrails and downstream automation to weaponize LLM interactions. First, they update a guardrail attached to a Bedrock conversational agent so that prompts containing words like “How” or “What” are blocked and replaced with a malicious block message that instructs users to download a PDF from an attacker-controlled URL, using the LLM chat interface to deliver malware through otherwise “safety” infrastructure.
In a closely related variant, the attacker targets a code-generation model whose outputs are executed by an AWS Lambda function; they poison the guardrail’s block message with Python code that, when passed downstream and executed, exfiltrates the Lambda role’s credentials to an attacker-controlled IP, granting the adversary complete control over the LLM application’s business logic layer. With those cloud credentials, the attacker enumerates Bedrock agents, knowledge bases, and data sources, repoints the RAG knowledge base to an attacker-controlled Simple Storage Service (S3) bucket to poison LLM responses with tampered content, and finally uses S3 access (for example, via aws s3 sync ) to exfiltrate sensitive inference data, including user prompts and proprietary information driving the LLM’s behavior.
Cost of Impact: 5 (Severe)
Victims of cloud ransomware attacks incur high costs monetarily, operationally, and reputationally. Even when victims refuse to negotiate, critical data and systems are effectively rendered useless depending on the method used to deny access to these assets.
Commonality: 3 (Moderate)
Based on a comparison of cloud ransomware events observed throughout the past year to reporting, cloud ransomware events continue to be monitored periodically, but they are not represented in high volumes.
Evolution Potential: 4 (High)
Threat actors have demonstrated in the past year that they are continuously identifying novel methods to perform cloud ransomware attacks. While the majority of these attacks still rely on threat actors’ use of native cloud services to perform the attacks, the methods they employ (and the theoretical methods threat researchers have reported) indicate that additional attack methods will likely surface in the future.
Effort to Perform: 4 (High)
Similar to Insikt Group’s determinations in reporting, threat actors’ reliance on cloud services to perform cloud ransomware operations ensures that an in-depth knowledge of cloud service provider (CSP) environments will remain necessary to perform cloud ransomware attacks.
Cloud ransomware operations exploit trusted access to cloud environments to encrypt cloud assets or render them inaccessible; this includes object storage, virtual disks, databases, and backups. Instead of deploying large numbers of binaries, threat actors use compromised accounts, roles, tokens, and keys to change encryption settings, rotate or destroy key material, or mass-modify stored data through cloud APIs and consoles. This keeps activity primarily within typical administrative paths and forces defenders to rely on behavioral indicators, such as unusual spikes in encryption, snapshot changes, or bulk storage operations.
Cloud ransomware will continue to rely on native cloud services to rapidly encrypt large volumes of cloud data or render them inaccessible.
Due to the managed nature of CSP environments, which were the only targets identified in cloud ransomware reporting during the past year, threat actors must rely on native services to encrypt or destroy data during a cloud ransomware campaign. Since these native services provide threat actors with the functionality needed to perform destructive actions against targeted assets, threat actors will also continue to need privileged access within victim cloud environments to perform cloud ransomware attacks effectively.
Figure 7 illustrates a hypothetical cloud ransomware attack chain and identifies parts of the attack chain where defenders can most efficiently hunt for and mitigate behaviors associated with it.
① Threat Actor Access to Victim Cloud Environment
In all events observed throughout the past year, threat actors had to first gain trusted access to the victim environment. This access, which grants the threat actor heightened privileges within the environment, is necessary to perform cloud ransomware attacks, since cloud ransomware attack chains rely on cloud service abuse for encryption, exfiltration, and persistence actions later.
Mitigation and hunting strategies for this behavior are discussed in the section titled Credential Abuse, Account Takeover, and Unauthorized Access . ② Discovery to Support Cloud Ransomware Activities
After initial access is established, threat actors will profile the cloud environment, performing discovery to identify assets for encryption and services that can be abused to support functions necessary for the cloud ransomware attack to succeed.
Common mitigation and threat hunting capabilities for this behavior include the following:
③ Cloud Service Abuse for Encryption or Denial of Access
Based on the events discussed later in this section, threat actors rely on native cloud services to conduct the action encryption of cloud assets or to deny users access to these assets.
Due to the fact that the methods Insikt Group observed only affected AWS and Azure environments, specific mitigation and hunting suggestions for each platform are shown below:
④ Establishment of Exfiltration and Persistence Channels
Before encryption or deletion actions, threat actors will often attempt to establish channels between the victim environment and their own infrastructure that will be used to exfiltrate the data they are making inaccessible to support double extortion. Additionally, either before or after the encryption or deletion of data, threat actors will establish a persistence channel, which will be used to restore access to the compromised data and, in some instances, maintain communications with the victim for negotiation purposes.
Common mitigation and threat hunting capabilities for this behavior include the following:
Insikt Group curated a list of events published during 2025 that demonstrate the threats posed by cloud ransomware attacks. These even...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
