Hackers Abuse VPS Infrastructure for Stealth, Speed
ID: 3eb7d2c1-bd6c-5c41-87e8-bb9e6697e8a5
STIX ID: report--3eb7d2c1-bd6c-5c41-87e8-bb9e6697e8a5
Feed Name: Dark Reading
Darktrace observed a series of May incidents in which threat actors used inexpensive VPS providers (Hyonix, Host Universal, Mevspace, Hivelocity) to spin up attack infrastructure, perform probable session hijacking and MFA token claim abuse, create obfuscated mailbox rules, delete emails (e.g., invoice-related messages), and potentially distribute spam. The attacks highlight an emerging TTP of abusing clean, quickly provisioned VPS endpoints to mimic legitimate traffic, evade geolocation and IP-reputation checks, and maintain persistence in SaaS environments; defenders are advised to monitor for improbable travel, unusual login sources, and mailbox rule changes and to adopt behavioral detection with autonomous response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
