Attackers Abuse Trusted Cloud Services to Hide Malicious Traffic
Cybercriminals are increasingly manipulating trusted cloud infrastructure from major providers like Amazon Web Services, Google Cloud, Microsoft Azure, and Cloudflare to hide malicious traffic and sustain command and control operations. Instead of hosting attacks on easily identifiable malicious servers, threat actors now embed their activities within legitimate cloud service traffic. This makes traditional reputation and blocklist–based security controls less effective and complicates detection for enterprise SOC teams. Security teams must treat cloud abuse as a serious risk vector, not just a compliance or operational concern. What Happened: Recent threat intelligence analyses have exposed a pattern where attackers consistently route malicious traffic through reputable cloud service providers. Investigations show cloud infrastructure from AWS, Google Cloud, Microsoft, and Cloudflare being used to host command and control (C2) traffic, phishing payloads, credential harvesting pages, a...