CTI Project: Threats Leveraging Legitimate Services
ID: 3b3fb1db-a7d8-5ddf-9755-ecdacc0d16b4
STIX ID: report--3b3fb1db-a7d8-5ddf-9755-ecdacc0d16b4
Feed Name: BushidoToken Blog
This report details how cybercriminals and nation-state actors increasingly weaponise legitimate cloud and PaaS services (CDNs, file-sharing, marketing platforms, DDNS, etc.) to host phishing pages, deliver malware, provide C2 channels (including dead-drop resolvers) and exfiltrate data. It references multiple observed campaigns and families (e.g., BazarLoader/Trickbot, Conti, DropboxAES/Crutch, ScreenConnect abuses), highlights the operational benefits attackers gain in evading detection, and warns defenders about the difficulty of blocking widely trusted services without impacting legitimate business use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
