Over the past month, cloud security analysts have seen malware increasingly spread from one PC to another in a fan-out phenomenon, thanks to file-sharing and file-syncing applications, Netskope, a Cloud Access Security Broker (CASB), reports in its February 2016 Worldwide Cloud Report
Malware discovered to spread via cloud accounts ranges from simple worms to complex ransomware. In most cases, the malware is simply copied and users must execute it.
Netskope says the cases it detected were more like accidents, but there were a lot of them. The company reports that 4.1% of all cloud-based applications scanned contained some type of malware.
They also say that they only scanned established (official) cloud applications, which represent only 5% of all cloud-based applications, and that the total number of cloud applications that coexist with malware or may contribute to the spread of malware is much higher than 4.1%.
While many people praise cloud-based services due to the growth in productivity, a recent report by Netskope should be taken as a warning sign and companies should be very careful when deploying such applications in the future.
Most users and system administrators often only see the positive features that cloud-based applications can bring, and many fail to see how these applications can be abused to spread malware.
For example, Dropbox was used to send spam to dating sites last December, while a Chinese group that received state-sponsored cyber-espionage was previously used to hide its C&C servers.
Due to its 99.99% guaranteed uptime record, malware authors are starting to target and incorporate these services as a key component in their malware.
Considering what Netskope has uncovered, it wouldn't be surprising to see a ransomware family specifically targeting Dropbox, OneDrive, or Google Drive sync folders to spread to other computers.

