Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is abuse of a trusted cloud service?

Abuse of a trusted cloud service occurs when an offender uses a legitimate provider for unauthorised storage, delivery, communication, execution or identity activity. The provider may be functioning normally while an account, object or feature is used for a harmful purpose.

Traffic to a familiar cloud domain is therefore not enough to classify the activity as benign or malicious.

Identify the service object, not just the provider

Major providers use shared addresses, encrypted connections and common domains for many unrelated customers. A network record naming only the provider may not reveal which tenant, storage object, function, repository, webhook or message channel was involved.

Useful detail can include:

  • tenant, account and object identifiers;
  • request path, API method and operation;
  • authentication token, key or application identity;
  • source process and device;
  • uploaded, downloaded or executed content; and
  • linked endpoint activity and provider audit events.

These features can distinguish an ordinary application request from access to a particular attacker-controlled object.

Separate service trust from account control

The relevant cloud account may have been created for the activity, rented or taken from another victim. Recovery changes, new tokens, API keys, application passwords and sharing events can help reconstruct changes in control. Current ownership does not necessarily describe control at the incident time.

Likewise, evidence that a provider hosted content does not show that the provider knew its purpose. State separately what the service did, what the account did and what evidence supports offender control.

Key takeaway

Resolve trusted-cloud activity to the exact account, object and operation, then distinguish provider infrastructure, subscriber identity and control at the relevant time.

Reference: CIM-262Cyber Incidents & Offender Methods