Cyber Attackers Exploit Cloud APIs with Advanced Phishing Tactics

ReliaQuest’s recently published report reveals disturbing methods employed by cyber attackers to exploit cloud environments, shedding light on some sophisticated tactics they use to bypass security measures. Analyzing true-positive alerts from December 2023 to September 2024, the report particularly focuses on how initial access and discovery commands are executed against public-facing cloud APIs. Notably, 28% of these alerts originated from self-service password reset requests, signaling determined attempts to gain administrator privileges. Within Kubernetes environments, the GetVersion command emerged in 31% of alerts, indicating active probing for software vulnerabilities.

A significant revelation from the report points to the extensive use of known malicious IP addresses in over half of the analyzed attacks, illustrating frequent scanning for exploitable vulnerabilities. A novel phishing technique has also come to light, involving the use of cloud-storage SaaS platforms like OneNote through SharePoint or Google Drive to host malicious links. Attackers skillfully employ phishing emails to direct recipients to these legitimate platforms, which complicates detection efforts for traditional security systems.

The Evolution of Phishing Tactics

Phishing, constituting 71.1% of the observed techniques in 2023, exploits users’ trust in familiar platforms such as Google Drive or Dropbox. Traditional email filtering systems may not consistently recognize these emails as malicious, permitting them to evade initial lines of defense. Recognizing this, ReliaQuest has developed detection rule libraries and GreyMatter containment and response playbooks to bolster security measures, operating independently of standard email tools.

The report underscores the menace of cloud environment hijacking, which could lead to misuse for activities like cryptocurrency mining or launching additional phishing schemes utilizing compromised resources. To counter these threats, strict monitoring and effective management of API keys are imperative. Implementing API gateways equipped with SSL certificates is recommended for added layers of identity verification, providing a more secure shield against potential intrusions.

Strategic Security Enhancements

ReliaQuest’s latest report uncovers alarming methods cyber attackers use to compromise cloud environments, highlighting sophisticated tactics to bypass security defenses. Analyzing true-positive alerts from December 2023 to September 2024, the report emphasizes the strategies used in initial access and discovery commands targeting public-facing cloud APIs. Strikingly, 28% of these alerts stemmed from self-service password reset requests, suggesting determined efforts to acquire administrator privileges. In Kubernetes systems, the GetVersion command appeared in 31% of alerts, signifying active probing for software weaknesses.

The report also highlights the pervasive use of known malicious IP addresses in over half of the analyzed attacks, underscoring frequent scans for vulnerabilities. Additionally, a new phishing technique has emerged, leveraging cloud-storage SaaS platforms like OneNote via SharePoint or Google Drive to host malicious links. Attackers craft phishing emails directing victims to these legitimate platforms, complicating detection for traditional security systems. This evolving threat landscape underscores the need for enhanced security measures to protect cloud environments.

Explore more

Is the Mistic Backdoor Hiding in Your Security Tools?

Introduction The emergence of the Mistic backdoor represents a sophisticated advancement in the arsenal of modern cybercriminals, specifically those operating within the niche of Initial Access Brokering (IAB). This malicious software, also identified by some security researchers as MLTBackdoor, has been actively infiltrating corporate environments throughout the first half of 2026. Its primary strength lies in its ability to camouflage

Is the Redmi 17C the New King of Budget Smartphones?

Dominic Jainy is a seasoned IT professional with a deep understanding of how hardware evolution impacts the budget mobile market. Today, he breaks down Xiaomi’s latest strategic move with the Redmi 17C, a device that surprisingly leaps over a generation to deliver high-refresh-rate displays and massive battery life to the entry-level segment. We explore the balance between essential utility features,

How Can PowerTool Speed Up Business Central Data Migrations?

Modern enterprises frequently encounter significant friction during ERP transitions because traditional data migration methods often fail to accommodate the sheer volume and complexity of contemporary datasets. In 2026, the demand for agility within Microsoft Dynamics 365 Business Central has reached a point where standard configuration packages, while functional for small tasks, often act as a bottleneck for larger implementations. The

How to Move Beyond the Portal to a True Developer Platform?

Dominic Jainy stands at the forefront of the modern cloud-native movement, possessing a deep technical mastery of artificial intelligence, machine learning, and blockchain architectures. With years of experience navigating the complexities of large-scale IT infrastructures, he has become a leading voice in the evolution of platform engineering. His perspective is shaped by the practical realities of moving beyond simple automation

Will AI Token Costs Soon Surpass Developer Salaries?

Recent financial projections indicate that the cost of maintaining high-frequency artificial intelligence interactions is rapidly approaching the median annual compensation of experienced software engineers in the global market. As the software development industry undergoes a radical transformation, the traditional overhead associated with human labor is being challenged by the sheer volume of data processed through large language models. This shift