BushidoUK / Abused-Legitimate-Services

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Abused Legitimate Services

Legitimate third-party Platform-as-a-Service (PaaS) providers are becoming increasingly leveraged by threat actors for phishing and malware deployment. PaaS providers such as cloud instances, marketing platforms, content delivery networks (CDN), and dynamic DNS servers have been weaponised for a range of malicious activities. One of the key benefits is that they can be used to evade detection systems. This is due to the decreased likelihood of these being pre-emptively blocked because of established levels of trust and legitimate usage.

Detailed analysis in the blog here: https://blog.bushidotoken.net/2021/11/leveraging-legitimate-services-for.html

Abused Legitimate Services by Malware campaigns

Abused Legitimate Services by Phishing campaigns

Papers

About

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups