HomeSecurityWhy are hackers turning to cloud storage services?

Why are hackers turning to cloud storage services?

Cybersecurity researchers are detailing attacks that exploit legitimate cloud services in attempts to access sensitive data.

Why are hackers turning to cloud storage services?

See also: How many data records containing usernames and passwords were breached in 2021?

A hacking and cyberespionage campaign is abusing legitimate cloud services as part of a covert operation to steal sensitive information from high-profile targets.

Organizations around the world are using cloud services to conduct daily operations, especially after the shift towards hybrid working. Cloud applications provide a simple means of working, regardless of where the user is located, which has become vital for employees working remotely.

However, it's not just businesses and employees who can benefit from cloud services.

And according to cybersecurity researchers at Unit 42 at Palo Alto Networks, that's exactly what hackers working on behalf of an advanced persistent threat (APT) group called Cloaked Ursa – also known as APT29, Nobelium, and Cozy Bear – are doing.

The Cloaked Ursa group is widely believed to be linked to the Russian Foreign Intelligence Service (SVR), responsible for several major cyberattacks, including the SolarWinds, the hack of the US Democratic National Committee (DNC), and espionage campaigns targeting governments and embassies around the world.

They are now trying to use legitimate cloud services, including Google Drive and Dropbox – and have already used this tactic as part of attacks carried out between May and June of this year.

See also: Roaming Mantis malware campaign targets Android and iOS users in France

The attacks begin with phishing messages sent to European embassy targets , which present themselves as invitations to meetings with ambassadors, with a supposed agenda attached as a PDF.

cloud

The PDF is malicious and, if executed as intended, will call a Dropbox account managed by the attackers to secretly deliver Cobalt Strike to the victim's device. However, this initial call was unsuccessful earlier this year, which researchers say is due to restrictive policies on corporate networks regarding the use of third-party services.

But the attackers adapted, sending similar phishing messages as a second lure, but instead used communication with Google Drive accounts to hide their actions and deploy Cobalt Strike payloads and malware in targeted environments. It appears that this warning was not blocked , likely because many workplaces use Google apps as part of their daily operations , so blocking Drive would cause a productivity issue .

Like many campaigns of this nature, the intent was likely to use malware to create a backdoor into an infected network and steal sensitive information , either for use in further attacks or for exploitation in other ways. Unit 42 has not clarified whether the campaigns successfully penetrated networks or not.

Unit 42 has notified both Dropbox and Google about abuse of their services, and action has been taken against accounts used as part of attacks.

Using cloud services provides many benefits for both businesses and staff – but it is important to ensure that the security of cloud applications and services is done properly to prevent hackers from exploiting these tools.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS