Cloud storage lockers from Microsoft and Google used to store and spread state-sponsored malware
ID: c9645ed3-51e2-5cd9-a7aa-263d3e24ec85
STIX ID: report--c9645ed3-51e2-5cd9-a7aa-263d3e24ec85
Feed Name: The Register (Security)
Symantec researchers presented at Black Hat that multiple nation-state and criminal groups are increasingly abusing legitimate cloud services (Microsoft Graph/OneDrive, Google Drive, GitHub) to host C2, deliver malware, and exfiltrate data; observed malware families include Grager, Moon_Tag and Onedrivetools, with infection chains using typosquatted installers, tunneled traffic (Whipweave/ORB), and automated OneDrive-based alerts and exfiltration, and Symantec published IOCs and MITRE mappings to help defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
