logo

Attackers Exploit Cloud Logging Platforms to Hide Malicious Activity

ID: 6340d056-d81d-5291-ab85-3ab3c1cc8f6e

STIX ID: report--6340d056-d81d-5291-ab85-3ab3c1cc8f6e

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Divya

...
...

This report describes how attackers are actively abusing cloud logging infrastructure—including AWS CloudTrail and Google Cloud Logging—to blind defenders and maintain persistent access by stopping log collection, deleting storage, altering KMS/CMEK keys to render logs unreadable, poisoning log files, and redirecting logs to attacker-controlled locations; it highlights the impact on detection and forensics and recommends tightening access controls, limiting permissions, and leveraging immutable/log-integrity features.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.