logo

CTI Project: Threats Leveraging Legitimate Services

ID: 3b3fb1db-a7d8-5ddf-9755-ecdacc0d16b4

STIX ID: report--3b3fb1db-a7d8-5ddf-9755-ecdacc0d16b4

Feed Name: BushidoToken Blog

Threat Score
75/100

Date Published: 2022-02-08

Date Updated: 2026-07-22

...
...

This report details how cybercriminals and nation-state actors increasingly weaponise legitimate cloud and PaaS services (CDNs, file-sharing, marketing platforms, DDNS, etc.) to host phishing pages, deliver malware, provide C2 channels (including dead-drop resolvers) and exfiltrate data. It references multiple observed campaigns and families (e.g., BazarLoader/Trickbot, Conti, DropboxAES/Crutch, ScreenConnect abuses), highlights the operational benefits attackers gain in evading detection, and warns defenders about the difficulty of blocking widely trusted services without impacting legitimate business use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.