logo

Cloud storage lockers from Microsoft and Google used to store and spread state-sponsored malware

ID: c9645ed3-51e2-5cd9-a7aa-263d3e24ec85

STIX ID: report--c9645ed3-51e2-5cd9-a7aa-263d3e24ec85

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-08-08

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Symantec researchers presented at Black Hat that multiple nation-state and criminal groups are increasingly abusing legitimate cloud services (Microsoft Graph/OneDrive, Google Drive, GitHub) to host C2, deliver malware, and exfiltrate data; observed malware families include Grager, Moon_Tag and Onedrivetools, with infection chains using typosquatted installers, tunneled traffic (Whipweave/ORB), and automated OneDrive-based alerts and exfiltration, and Symantec published IOCs and MITRE mappings to help defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.