Threats Tagged 'cloud infrastructure abuse'
View all threats tagged with 'cloud infrastructure abuse'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cloud infrastructure abuse'
Click on any threat for detailed analysis and mitigation recommendations
An investigation reveals a thriving underground economy of fraudulent account marketplaces that openly sell verified accounts across major platforms including email providers, social media, cloud services, and payment processors. These operations exploit lax fraud prevention by major tech companies, which often prioritize user growth metrics over security. The report identifies numerous Chinese, Vietnamese, and English-language websites selling accounts for services like Gmail, AWS, Stripe, TikTok, and Reddit at prices ranging from $1 to $300. These marketplaces offer fresh accounts, aged accounts with established trust signals, and hijacked high-karma accounts. The investigation highlights how internal corporate pressures to inflate user adoption numbers create security vulnerabilities, with some companies admitting up to 14% of their user base may be fraudulent. Join the discussion | AlienVault OTX General | 08/05/2026, 13:12:01 UTC Added: 08/06/2026, 08:56:14 UTC |
Google Threat Intelligence Group identified a sophisticated intrusion campaign by UNC6692 that combined persistent social engineering with custom malware. The attackers impersonated IT helpdesk personnel via Microsoft Teams, leveraging initial email spam campaigns to create urgency. Victims were tricked into downloading AutoHotKey scripts that installed SNOWBELT, a malicious browser extension establishing persistence through scheduled tasks. The modular SNOW ecosystem enabled deep network penetration: SNOWBELT provided initial access, SNOWGLAZE created encrypted WebSocket tunnels masking traffic as legitimate cloud communications, and SNOWBASIN functioned as a local backdoor for command execution. UNC6692 performed internal reconnaissance, escalated privileges by extracting LSASS memory, and used Pass-The-Hash techniques to access domain controllers. The operation culminated in exfiltration of Active Directory databases and credentials via LimeWire, demonstrating advanced tradecraft abusing legitimate clou... Join the discussion | AlienVault OTX General | 04/23/2026, 19:25:55 UTC Added: 04/24/2026, 09:06:03 UTC |
Showing 1 to 2 of 2 results