Know
What is Living off the Cloud?
Living off the cloud extends the living-off-the-land idea to hosted environments. Instead of importing obvious malicious tooling, attackers use the organization’s existing cloud services, APIs, credentials, storage, serverless functions, Kubernetes, SaaS integrations, and administrative features to move, persist, and exfiltrate data.
Why it matters
Google Cloud’s 2026 Cloud Threat Horizons reporting describes attackers pivoting from compromised endpoints into Kubernetes and cloud infrastructure and using legitimate cloud services for data theft. Cloud-conscious eCrime activity also surged in CrowdStrike’s 2026 threat hunting data.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Google documents agent-enabled credential harvesting and AI resource theft
Google's September 8 report describes a Q2 2026 case in which attackers compromised a cloud resource and planned, built, and executed an agent-enabled credential-harvesting campaign in under six hours. It also documents theft of AI credentials and unauthorized use of victim cloud resources.
The timeline describes one observed case, not an industry average or a claim that all attacks are autonomous. The report is newly published; the described activity occurred earlier.
Cloud and SaaS incidents were dominated by identity compromise and data theft
Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.
The report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.
CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours
CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.
These measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.
Understand the mechanics
How it works
- 1
Compromise a cloud-capable identity or endpoint.
- 2
Discover accessible cloud services, APIs, roles, and secrets.
- 3
Use native administration and automation rather than obvious malware.
- 4
Move data through approved cloud storage or services.
- 5
Maintain access using legitimate identities, tokens, workloads, or integrations.
Practice
What to watch for
- Unusual API calls by valid identities
- New cloud resources or serverless functions
- Bulk data movement to legitimate storage
- Cross-service role assumption
- Kubernetes or cloud admin activity from a user who does not normally perform it
Perform
What to do
- 1
Revoke compromised identities and workload credentials.
- 2
Preserve cloud control-plane and data-access logs.
- 3
Identify attacker-created resources and persistence.
- 4
Review IAM paths and connected workloads.
- 5
Contain data egress while preserving evidence.
How to reduce the risk
- Cloud-native logging
- Least privilege
- Workload identity
- Egress monitoring
- CSPM/CNAPP
- Short-lived credentials
- Behavior analytics
- Separate admin roles
Business impact
- Silent cloud persistence
- Data theft
- Cryptocurrency theft
- Resource abuse
- Difficult attribution because legitimate tools are used
What different roles should do
Cloud Engineering
- Treat control-plane activity as security telemetry
Security
- Detect abnormal sequences of legitimate cloud actions, not only malware signatures
Framework & standards context
- MITRE ATT&CK Cloud techniques
- NIST CSF 2.0 Detect
Source transparency
Authoritative sources
Last reviewed: 2026-09-02