Hiding in the Cloud

Aug 4, 2015 | Cloud, Data, Security

Featured article by Ken Westin, Security Analyst for Tripwire

Researchers have detected Russian hackers operating in plain sight using the cover of legitimate services including Twitter, Github and cloud storage services to steal data from organizations during the work day. Recently, a cyber gang known as APT29 created malware called Hammertoss which is very hard to detect. Using a variety of Twitter handles daily, they are able to send commands to infected machines using images embedded with encrypted command information, these commands allow them to upload the stolen information to cloud storage services. They also infect legitimate web servers and usethem as part of their command and control infrastructure. A Hammertoss compromise to the cloud based back-end infrastructure that supports many services could result in the breach of a huge number of organizations.

This particular method of attack is pretty clever because it takes advantage of most enterprise organizations trust and white listing of well-known social media and cloud service platforms. By downloading binary images and embedding commands in the images they easily circumvent most detection mechanisms. The additional measure of encrypting the message within the image serves a double purpose of hiding the messages in the image in case it is intercepted, as well cloaking the messages in order to bypass any steganography detection tools an organization may have in place.  Encrypted data in the image makes steganography detection harder because encrypted data generally has a high degree of randomness making it much less suspicious, especially when embedded in image data.

Companies under attack from this malware would typically not be aware that their network is under attack because Hammertoss looks for a designated Twitter handle that contains a Tweet with a url and hashtag. The malware is then directed to the URL where it automatically decrypts encoded instructions from an image and then is able to steal files. Once the files have been obtained, they are exfiltrated to a cloud storage service.

The APT29 group operates out of Russia, and based on a number of factors FireEye researchers believed it to be sponsored by the Russian government. The group is clever in the way they developed this tool because its communication appears to be legitimate traffic. Many organizations utilize threat intelligence feeds to assist in the detection and blocking of known IP addresses and hosts associated with malware along with command and control infrastructure that precipitates other malicious activities. By utilizing services like Twitter and Github, this malware is able to leverage hosts and IPs that are more likely white listed by a given organization.

Organizations can protect themselves by ensuring critical infrastructure is not communicating with any of these services. A server running a critical application, for example, should not be communicating with Twitter or Github or any other cloud based service. This can be a challenge when we are looking at endpoints such as laptops or desktops being used by employees, as the goal of this particular attack method is to appear to belegitimate traffic. However, the malware itself has to be installed on the target system before it can begin its communications with these services, so organizations first and best defense is to block the installation of the malware in the first place. This is especially true for critical infrastructure; any binaries or files installed on these systems should be detected easily with file integrity monitoring and other endpoint security monitoring tools.

Once data is exfiltrated to a cloud based service it should be assumed the data is compromised. Even if you are able to get the data removed from the service it’s reasonable to assume that the data has most likely has automatically been downloaded or backed up to a different service either directly or indirectlyby the attackers.

ken

About the Author

Ken Westin is an experienced security researcher and analyst that has worked with law enforcement and journalists to uncover organized cybercrime rings with a special focus on incident detection, forensics and threat intelligence.

 

Top 10 Cybersecurity Stories This Week: FBI Warns FortiBleed Is Locking Admins Out of Their Own Firewalls, Attackers Hijack Three Country-Code Domain Registries to Obtain 12 Google HTTPS Certificates, ShinyHunters Suspect Arrested in Jordan

Top 10 Cybersecurity Stories This Week: FBI Warns FortiBleed Is Locking Admins Out of Their Own Firewalls, Attackers Hijack Three Country-Code Domain Registries to Obtain 12 Google HTTPS Certificates, ShinyHunters Suspect Arrested in Jordan

October 9, 2026 | ITBriefcase.net Why it matters: The FBI and US Secret Service issued a joint advisory on October 6 confirming that the FortiBleed credential-harvesting campaign — which has compromised credentials for 86,644 Fortinet FortiGate firewalls and SSL VPN...

read more
Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more