logo

Hackers Abuse VPS Infrastructure for Stealth, Speed

ID: 3eb7d2c1-bd6c-5c41-87e8-bb9e6697e8a5

STIX ID: report--3eb7d2c1-bd6c-5c41-87e8-bb9e6697e8a5

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-08-21

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Darktrace observed a series of May incidents in which threat actors used inexpensive VPS providers (Hyonix, Host Universal, Mevspace, Hivelocity) to spin up attack infrastructure, perform probable session hijacking and MFA token claim abuse, create obfuscated mailbox rules, delete emails (e.g., invoice-related messages), and potentially distribute spam. The attacks highlight an emerging TTP of abusing clean, quickly provisioned VPS endpoints to mimic legitimate traffic, evade geolocation and IP-reputation checks, and maintain persistence in SaaS environments; defenders are advised to monitor for improbable travel, unusual login sources, and mailbox rule changes and to adopt behavioral detection with autonomous response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.